From 250ac961c138aa67757a20d517f8d0c9a99b49d1 Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Fri, 22 Nov 2024 00:26:44 +0100 Subject: [PATCH 001/166] nagstamon: move to by-name Co-authored-by: liberodark --- .../default.nix => by-name/na/nagstamon/package.nix} | 8 ++++---- pkgs/top-level/all-packages.nix | 4 ---- 2 files changed, 4 insertions(+), 8 deletions(-) rename pkgs/{tools/misc/nagstamon/default.nix => by-name/na/nagstamon/package.nix} (73%) diff --git a/pkgs/tools/misc/nagstamon/default.nix b/pkgs/by-name/na/nagstamon/package.nix similarity index 73% rename from pkgs/tools/misc/nagstamon/default.nix rename to pkgs/by-name/na/nagstamon/package.nix index f004ad9b42fd..9dfe9ac9067e 100644 --- a/pkgs/tools/misc/nagstamon/default.nix +++ b/pkgs/by-name/na/nagstamon/package.nix @@ -1,6 +1,6 @@ -{ lib, fetchurl, pythonPackages }: +{ lib, fetchurl, python3Packages }: -pythonPackages.buildPythonApplication rec { +python3Packages.buildPythonApplication rec { pname = "nagstamon"; version = "3.14.0"; @@ -12,8 +12,8 @@ pythonPackages.buildPythonApplication rec { # Test assumes darwin doCheck = false; - build-system = with pythonPackages; [ setuptools ]; - dependencies = with pythonPackages; [ configparser pyqt6 psutil requests + build-system = with python3Packages; [ setuptools ]; + dependencies = with python3Packages; [ configparser pyqt6 psutil requests beautifulsoup4 keyring requests-kerberos lxml dbus-python python-dateutil pysocks ]; meta = with lib; { diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 4bd94a560651..e8bb70705d8f 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -4258,10 +4258,6 @@ with pkgs; mx-puppet-discord = callPackage ../servers/mx-puppet-discord { }; - nagstamon = callPackage ../tools/misc/nagstamon { - pythonPackages = python3Packages; - }; - nanoemoji = with python3Packages; toPythonApplication nanoemoji; nbtscanner = callPackage ../tools/security/nbtscanner { From 697286bf4dd701fb2e55ac51251f9561c6b8cbf2 Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Fri, 22 Nov 2024 00:28:31 +0100 Subject: [PATCH 002/166] nagstamon: format Co-authored-by: liberodark --- pkgs/by-name/na/nagstamon/package.nix | 26 ++++++++++++++++++++++---- 1 file changed, 22 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/na/nagstamon/package.nix b/pkgs/by-name/na/nagstamon/package.nix index 9dfe9ac9067e..f09082bdd197 100644 --- a/pkgs/by-name/na/nagstamon/package.nix +++ b/pkgs/by-name/na/nagstamon/package.nix @@ -1,4 +1,8 @@ -{ lib, fetchurl, python3Packages }: +{ + lib, + fetchurl, + python3Packages, +}: python3Packages.buildPythonApplication rec { pname = "nagstamon"; @@ -13,13 +17,27 @@ python3Packages.buildPythonApplication rec { doCheck = false; build-system = with python3Packages; [ setuptools ]; - dependencies = with python3Packages; [ configparser pyqt6 psutil requests - beautifulsoup4 keyring requests-kerberos lxml dbus-python python-dateutil pysocks ]; + dependencies = with python3Packages; [ + configparser + pyqt6 + psutil + requests + beautifulsoup4 + keyring + requests-kerberos + lxml + dbus-python + python-dateutil + pysocks + ]; meta = with lib; { description = "Status monitor for the desktop"; homepage = "https://nagstamon.de/"; license = licenses.gpl2Plus; - maintainers = with maintainers; [ pSub liberodark ]; + maintainers = with maintainers; [ + pSub + liberodark + ]; }; } From 3b41ec0691a44b18b761731324fa7a95e37c0e38 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Sun, 17 Nov 2024 13:01:22 +0000 Subject: [PATCH 003/166] nixos-rebuild-ng: explicitly parse Nix flags --- pkgs/by-name/ni/nixos-rebuild-ng/README.md | 2 +- .../src/nixos_rebuild/__init__.py | 104 +++++++++++++++--- .../nixos-rebuild-ng/src/nixos_rebuild/nix.py | 29 +++-- .../src/nixos_rebuild/utils.py | 13 ++- .../nixos-rebuild-ng/src/tests/test_main.py | 24 ++-- .../ni/nixos-rebuild-ng/src/tests/test_nix.py | 8 +- .../nixos-rebuild-ng/src/tests/test_utils.py | 28 ++++- 7 files changed, 155 insertions(+), 53 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/README.md b/pkgs/by-name/ni/nixos-rebuild-ng/README.md index f023c949c1ef..d74eda27cdf4 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/README.md +++ b/pkgs/by-name/ni/nixos-rebuild-ng/README.md @@ -119,7 +119,7 @@ ruff format . ## TODO - [ ] Remote host/builders (via SSH) -- [ ] Improve nix arguments handling (e.g.: `nixFlags` vs `copyFlags` in the +- [x] Improve nix arguments handling (e.g.: `nixFlags` vs `copyFlags` in the old `nixos-rebuild`) - [ ] `_NIXOS_REBUILD_EXEC` - [ ] Port `nixos-rebuild.passthru.tests` diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py index 777cf05a07dd..4eba64daafb9 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py @@ -21,19 +21,19 @@ from .nix import ( switch_to_configuration, upgrade_channels, ) -from .utils import info +from .utils import flags_to_dict, info -VERBOSE = False +VERBOSE = 0 -def parse_args(argv: list[str]) -> tuple[argparse.Namespace, list[str]]: +def parse_args(argv: list[str]) -> argparse.Namespace: parser = argparse.ArgumentParser( prog="nixos-rebuild", description="Reconfigure a NixOS machine", add_help=False, allow_abbrev=False, ) - parser.add_argument("--help", action="store_true") + parser.add_argument("--help", "-h", action="store_true") parser.add_argument("--file", "-f") parser.add_argument("--attr", "-A") parser.add_argument("--flake", nargs="?", const=True) @@ -48,13 +48,44 @@ def parse_args(argv: list[str]) -> tuple[argparse.Namespace, list[str]]: parser.add_argument("--upgrade-all", action="store_true") parser.add_argument("--json", action="store_true") parser.add_argument("action", choices=Action.values(), nargs="?") + parser.add_argument("--verbose", "-v", action="count", default=0) - args, remainder = parser.parse_known_args(argv[1:]) + common_group = parser.add_argument_group("Common flags") + common_group.add_argument("--include", "-I") + common_group.add_argument("--max-jobs", "-j") + common_group.add_argument("--cores") + common_group.add_argument("--log-format") + common_group.add_argument("--quiet", action="store_true") + common_group.add_argument("--print-build-logs", "-L", action="store_true") + common_group.add_argument("--show-trace", action="store_true") + common_group.add_argument("--keep-going", "-k", action="store_true") + common_group.add_argument("--keep-failed", "-K", action="store_true") + common_group.add_argument("--fallback", action="store_true") + common_group.add_argument("--repair", action="store_true") + common_group.add_argument("--option", nargs=2) + + nix_group = parser.add_argument_group("Classic Nix flags") + nix_group.add_argument("--no-build-output", "-Q", action="store_true") + + flake_group = parser.add_argument_group("Flake flags") + flake_group.add_argument("--accept-flake-config", action="store_true") + flake_group.add_argument("--refresh", action="store_true") + flake_group.add_argument("--impure", action="store_true") + flake_group.add_argument("--offline", action="store_true") + flake_group.add_argument("--no-net", action="store_true") + flake_group.add_argument("--recreate-lock-file", action="store_true") + flake_group.add_argument("--no-update-lock-file", action="store_true") + flake_group.add_argument("--no-write-lock-file", action="store_true") + flake_group.add_argument("--no-registries", action="store_true") + flake_group.add_argument("--commit-lock-file", action="store_true") + flake_group.add_argument("--update-input") + flake_group.add_argument("--override-input", nargs=2) + + args = parser.parse_args(argv[1:]) global VERBOSE - # Manually parse verbose flag since this is a nix flag that also affect - # the script - VERBOSE = any(v == "--verbose" or v.startswith("-v") for v in remainder) + # This flag affects both nix and this script + VERBOSE = args.verbose # https://github.com/NixOS/nixpkgs/blob/master/pkgs/os-specific/linux/nixos-rebuild/nixos-rebuild.sh#L56 if args.action == Action.DRY_RUN.value: @@ -76,11 +107,48 @@ def parse_args(argv: list[str]) -> tuple[argparse.Namespace, list[str]]: r = run(["man", "8", "nixos-rebuild"], check=False) parser.exit(r.returncode) - return args, remainder + return args def execute(argv: list[str]) -> None: - args, nix_flags = parse_args(argv) + args = parse_args(argv) + + common_flags = flags_to_dict( + args, + [ + "verbose", + "include", + "max_jobs", + "cores", + "log_format", + "quiet", + "print_build_logs", + "show_trace", + "keep_going", + "keep_failed", + "fallback", + "repair", + "option", + ], + ) + nix_flags = common_flags | flags_to_dict(args, ["no_build_output"]) + flake_flags = common_flags | flags_to_dict( + args, + [ + "accept_flake_config", + "refresh", + "impure", + "offline", + "no_net", + "recreate_lock_file", + "no_update_lock_file", + "no_write_lock_file", + "no_registries", + "commit_lock_file", + "update_input", + "override_input", + ], + ) profile = Profile.from_name(args.profile_name) flake = Flake.from_arg(args.flake) @@ -96,7 +164,7 @@ def execute(argv: list[str]) -> None: # untrusted tree. can_run = action in (Action.SWITCH, Action.BOOT, Action.TEST) if can_run and not flake: - nixpkgs_path = find_file("nixpkgs", nix_flags) + nixpkgs_path = find_file("nixpkgs", **nix_flags) rev = get_nixpkgs_rev(nixpkgs_path) if nixpkgs_path and rev: (nixpkgs_path / ".version-suffix").write_text(rev) @@ -110,8 +178,8 @@ def execute(argv: list[str]) -> None: path_to_config = nixos_build_flake( "toplevel", flake, - nix_flags, no_link=True, + **flake_flags, ) set_profile(profile, path_to_config) else: @@ -119,8 +187,8 @@ def execute(argv: list[str]) -> None: "system", args.attr, args.file, - nix_flags, no_out_link=True, + **nix_flags, ) set_profile(profile, path_to_config) switch_to_configuration( @@ -142,18 +210,18 @@ def execute(argv: list[str]) -> None: path_to_config = nixos_build_flake( "toplevel", flake, - nix_flags, keep_going=True, dry_run=dry_run, + **flake_flags, ) else: path_to_config = nixos_build( "system", args.attr, args.file, - nix_flags, keep_going=True, dry_run=dry_run, + **nix_flags, ) if action in (Action.TEST, Action.DRY_ACTIVATE): switch_to_configuration( @@ -168,21 +236,21 @@ def execute(argv: list[str]) -> None: path_to_config = nixos_build_flake( attr, flake, - nix_flags, keep_going=True, + **flake_flags, ) else: path_to_config = nixos_build( attr, args.attr, args.file, - nix_flags, keep_going=True, + **nix_flags, ) vm_path = next(path_to_config.glob("bin/run-*-vm"), "./result/bin/run-*-vm") print(f"Done. The virtual machine can be started by running '{vm_path}'") case Action.EDIT: - edit(flake, nix_flags) + edit(flake, **flake_flags) case Action.DRY_RUN: assert False, "DRY_RUN should be a DRY_BUILD alias" case Action.LIST_GENERATIONS: diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py index fc2ba09dfffe..94dc1380844a 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py @@ -15,20 +15,27 @@ from .models import ( NRError, Profile, ) -from .utils import dict_to_flags, info +from .utils import Args, dict_to_flags, info FLAKE_FLAGS: Final = ["--extra-experimental-features", "nix-command flakes"] -def edit(flake: Flake | None, nix_flags: list[str] | None = None) -> None: +def edit(flake: Flake | None, **flake_flags: Args) -> None: "Try to find and open NixOS configuration file in editor." if flake: run( - ["nix", *FLAKE_FLAGS, "edit", *(nix_flags or []), "--", str(flake)], + [ + "nix", + *FLAKE_FLAGS, + "edit", + *(dict_to_flags(flake_flags)), + "--", + str(flake), + ], check=False, ) else: - if nix_flags: + if flake_flags: raise NRError("'edit' does not support extra Nix flags") nixos_config = Path( os.getenv("NIXOS_CONFIG") @@ -49,10 +56,10 @@ def edit(flake: Flake | None, nix_flags: list[str] | None = None) -> None: raise NRError("cannot find NixOS config file") -def find_file(file: str, nix_flags: list[str] | None = None) -> Path | None: +def find_file(file: str, **nix_flags: Args) -> Path | None: "Find classic Nixpkgs location." r = run( - ["nix-instantiate", "--find-file", file, *(nix_flags or [])], + ["nix-instantiate", "--find-file", file, *dict_to_flags(nix_flags)], stdout=PIPE, check=False, text=True, @@ -207,8 +214,7 @@ def nixos_build( attr: str, pre_attr: str | None, file: str | None, - nix_flags: list[str] | None = None, - **kwargs: bool | str, + **nix_flags: Args, ) -> Path: """Build NixOS attribute using classic Nix. @@ -227,7 +233,7 @@ def nixos_build( ] else: run_args = ["nix-build", "", "--attr", attr] - run_args += dict_to_flags(kwargs) + (nix_flags or []) + run_args += dict_to_flags(nix_flags) r = run(run_args, check=True, text=True, stdout=PIPE) return Path(r.stdout.strip()) @@ -235,8 +241,7 @@ def nixos_build( def nixos_build_flake( attr: str, flake: Flake, - nix_flags: list[str] | None = None, - **kwargs: bool | str, + **flake_flags: Args, ) -> Path: """Build NixOS attribute using Flakes. @@ -249,7 +254,7 @@ def nixos_build_flake( "--print-out-paths", f"{flake}.config.system.build.{attr}", ] - run_args += dict_to_flags(kwargs) + (nix_flags or []) + run_args += dict_to_flags(flake_flags) r = run(run_args, check=True, text=True, stdout=PIPE) return Path(r.stdout.strip()) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/utils.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/utils.py index 1cc210c3005a..704688a3a3c7 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/utils.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/utils.py @@ -1,18 +1,20 @@ from __future__ import annotations +import argparse import sys from functools import partial -from typing import Any +from typing import TypeAlias info = partial(print, file=sys.stderr) +Args: TypeAlias = bool | str | list[str] | int | None -def dict_to_flags(d: dict[str, Any]) -> list[str]: +def dict_to_flags(d: dict[str, Args]) -> list[str]: flags = [] for key, value in d.items(): flag = f"--{'-'.join(key.split('_'))}" match value: - case None | False: + case None | False | 0 | []: pass case True: flags.append(flag) @@ -26,3 +28,8 @@ def dict_to_flags(d: dict[str, Any]) -> list[str]: for v in value: flags.append(v) return flags + + +def flags_to_dict(args: argparse.Namespace, keys: list[str]) -> dict[str, Args]: + d = vars(args) + return {k: d[k] for k in keys} diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py index 3f4fcfe289d8..7af3e60846fb 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py @@ -29,25 +29,27 @@ def test_parse_args() -> None: nr.parse_args(["nixos-rebuild", "edit", "--attr", "attr"]) assert e.value.code == 2 - r1, remainder = nr.parse_args( + r1 = nr.parse_args( [ "nixos-rebuild", "switch", "--install-grub", "--flake", "/etc/nixos", - "--extra", - "flag", + "--option", + "foo", + "bar", ] ) - assert remainder == ["--extra", "flag"] + assert nr.VERBOSE == 0 assert r1.flake == "/etc/nixos" assert r1.install_bootloader is True assert r1.install_grub is True assert r1.profile_name == "system" assert r1.action == "switch" + assert r1.option == ["foo", "bar"] - r2, remainder = nr.parse_args( + r2 = nr.parse_args( [ "nixos-rebuild", "dry-run", @@ -57,9 +59,11 @@ def test_parse_args() -> None: "foo", "--attr", "bar", + "-vvv", ] ) - assert remainder == [] + assert nr.VERBOSE == 3 + assert r2.verbose == 3 assert r2.flake is False assert r2.action == "dry-build" assert r2.file == "foo" @@ -88,7 +92,6 @@ def test_execute_nix_boot(mock_which: Any, mock_run: Any, tmp_path: Path) -> Non nr.execute(["nixos-rebuild", "boot", "--no-flake", "-vvv"]) - assert nr.VERBOSE is True assert mock_run.call_count == 6 mock_run.assert_has_calls( [ @@ -164,7 +167,6 @@ def test_execute_nix_switch_flake(mock_run: Any, tmp_path: Path) -> None: ] ) - assert nr.VERBOSE is True assert mock_run.call_count == 3 mock_run.assert_has_calls( [ @@ -177,7 +179,7 @@ def test_execute_nix_switch_flake(mock_run: Any, tmp_path: Path) -> None: "--print-out-paths", "/path/to/config#nixosConfigurations.hostname.config.system.build.toplevel", "--no-link", - "--verbose", + "-v", ], check=True, text=True, @@ -209,8 +211,7 @@ def test_execute_switch_rollback(mock_run: Any, tmp_path: Path) -> None: nr.execute(["nixos-rebuild", "switch", "--rollback", "--install-bootloader"]) - assert nr.VERBOSE is False - assert mock_run.call_count == 3 + assert mock_run.call_count >= 2 # ignoring update_nixpkgs_rev calls mock_run.assert_has_calls( [ @@ -268,7 +269,6 @@ def test_execute_test_rollback( ] ) - assert nr.VERBOSE is False assert mock_run.call_count == 2 mock_run.assert_has_calls( [ diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py index 367c55c55695..e0468517ceca 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py @@ -16,7 +16,7 @@ from .helpers import get_qualified_name def test_edit(mock_run: Any, monkeypatch: Any, tmpdir: Any) -> None: # Flake flake = m.Flake.parse(".#attr") - n.edit(flake, ["--commit-lock-file"]) + n.edit(flake, commit_lock_file=True) mock_run.assert_called_with( [ "nix", @@ -193,8 +193,8 @@ def test_nixos_build_flake(mock_run: Any) -> None: assert n.nixos_build_flake( "toplevel", flake, - ["--nix-flag", "foo"], no_link=True, + nix_flag="foo", ) == Path("/path/to/file") mock_run.assert_called_with( [ @@ -220,9 +220,7 @@ def test_nixos_build_flake(mock_run: Any) -> None: return_value=CompletedProcess([], 0, stdout=" \n/path/to/file\n "), ) def test_nixos_build(mock_run: Any, monkeypatch: Any) -> None: - assert n.nixos_build("attr", None, None, ["--nix-flag", "foo"]) == Path( - "/path/to/file" - ) + assert n.nixos_build("attr", None, None, nix_flag="foo") == Path("/path/to/file") mock_run.assert_called_with( ["nix-build", "", "--attr", "attr", "--nix-flag", "foo"], check=True, diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_utils.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_utils.py index 98c0b798742c..bf6a404f984e 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_utils.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_utils.py @@ -1,8 +1,10 @@ +import argparse + from nixos_rebuild import utils as u def test_dict_to_flags() -> None: - r = u.dict_to_flags( + r1 = u.dict_to_flags( { "test_flag_1": True, "test_flag_2": False, @@ -12,7 +14,7 @@ def test_dict_to_flags() -> None: "verbose": 5, } ) - assert r == [ + assert r1 == [ "--test-flag-1", "--test-flag-3", "value", @@ -21,3 +23,25 @@ def test_dict_to_flags() -> None: "v2", "-vvvvv", ] + r2 = u.dict_to_flags({"verbose": 0, "empty_list": []}) + assert r2 == [] + + +def test_flags_to_dict() -> None: + r = u.flags_to_dict( + argparse.Namespace( + test_flag_1=True, + test_flag_2=False, + test_flag_3="value", + test_flag_4=["v1", "v2"], + test_flag_5=None, + verbose=5, + ), + ["test_flag_1", "test_flag_3", "test_flag_4", "verbose"], + ) + assert r == { + "test_flag_1": True, + "test_flag_3": "value", + "test_flag_4": ["v1", "v2"], + "verbose": 5, + } From 6c6d08dc4f0ab08add42da965a5e2a41bc83aff5 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Sun, 17 Nov 2024 18:26:45 +0000 Subject: [PATCH 004/166] nixos-rebuild-ng: add --sudo/--use-remote-sudo flags --- .../src/nixos_rebuild/__init__.py | 9 +++- .../src/nixos_rebuild/models.py | 15 ++++++ .../nixos-rebuild-ng/src/nixos_rebuild/nix.py | 9 ++-- .../src/nixos_rebuild/process.py | 22 +++++++++ .../nixos-rebuild-ng/src/tests/test_main.py | 12 +++-- .../nixos-rebuild-ng/src/tests/test_models.py | 11 ++++- .../ni/nixos-rebuild-ng/src/tests/test_nix.py | 13 +++-- .../src/tests/test_process.py | 47 +++++++++++++++++++ .../nixos-rebuild-ng/src/tests/test_utils.py | 2 +- 9 files changed, 125 insertions(+), 15 deletions(-) create mode 100644 pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py create mode 100644 pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py index 4eba64daafb9..fcb615eefa6e 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py @@ -47,6 +47,9 @@ def parse_args(argv: list[str]) -> argparse.Namespace: parser.add_argument("--upgrade", action="store_true") parser.add_argument("--upgrade-all", action="store_true") parser.add_argument("--json", action="store_true") + parser.add_argument("--sudo", action="store_true") + # TODO: add deprecated=True in Python >=3.13 + parser.add_argument("--use-remote-sudo", dest="sudo", action="store_true") parser.add_argument("action", choices=Action.values(), nargs="?") parser.add_argument("--verbose", "-v", action="count", default=0) @@ -181,7 +184,7 @@ def execute(argv: list[str]) -> None: no_link=True, **flake_flags, ) - set_profile(profile, path_to_config) + set_profile(profile, path_to_config, sudo=args.sudo) else: path_to_config = nixos_build( "system", @@ -190,10 +193,11 @@ def execute(argv: list[str]) -> None: no_out_link=True, **nix_flags, ) - set_profile(profile, path_to_config) + set_profile(profile, path_to_config, sudo=args.sudo) switch_to_configuration( path_to_config, action, + sudo=args.sudo, specialisation=args.specialisation, install_bootloader=args.install_bootloader, ) @@ -227,6 +231,7 @@ def execute(argv: list[str]) -> None: switch_to_configuration( path_to_config, action, + sudo=args.sudo, specialisation=args.specialisation, ) case Action.BUILD_VM | Action.BUILD_VM_WITH_BOOTLOADER: diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py index 0de155cf7b6a..7d9082824ed8 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py @@ -1,5 +1,6 @@ from __future__ import annotations +import os import platform import re from dataclasses import dataclass @@ -114,3 +115,17 @@ class Profile: path = Path("/nix/var/nix/profiles/system-profiles") / name path.parent.mkdir(mode=0o755, parents=True, exist_ok=True) return Profile(name, path) + + +@dataclass(frozen=True) +class SSH: + host: str + opts: list[str] + + @staticmethod + def from_arg(host: str | None) -> SSH | None: + if host: + opts = os.getenv("SSH_OPTS", "").split() + return SSH(host, opts) + else: + return None diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py index 94dc1380844a..bedd6a265879 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py @@ -4,7 +4,7 @@ import os import shutil from datetime import datetime from pathlib import Path -from subprocess import PIPE, CalledProcessError, run +from subprocess import PIPE, CalledProcessError from typing import Final from .models import ( @@ -15,6 +15,7 @@ from .models import ( NRError, Profile, ) +from .process import run from .utils import Args, dict_to_flags, info FLAKE_FLAGS: Final = ["--extra-experimental-features", "nix-command flakes"] @@ -280,14 +281,15 @@ def rollback_temporary_profile(profile: Profile) -> Path | None: return None -def set_profile(profile: Profile, path_to_config: Path) -> None: +def set_profile(profile: Profile, path_to_config: Path, sudo: bool) -> None: "Set a path as the current active Nix profile." - run(["nix-env", "-p", profile.path, "--set", path_to_config], check=True) + run(["nix-env", "-p", profile.path, "--set", path_to_config], check=True, sudo=sudo) def switch_to_configuration( path_to_config: Path, action: Action, + sudo: bool, install_bootloader: bool = False, specialisation: str | None = None, ) -> None: @@ -313,6 +315,7 @@ def switch_to_configuration( "LOCALE_ARCHIVE": os.getenv("LOCALE_ARCHIVE", ""), }, check=True, + sudo=sudo, ) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py new file mode 100644 index 000000000000..95a962904d68 --- /dev/null +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py @@ -0,0 +1,22 @@ +from __future__ import annotations + +import os +import subprocess +from typing import Any, Sequence + +from .models import SSH + + +def run( + args: Sequence[str | bytes | os.PathLike[Any]], + # make `check` explicit so we always know if the code is aborting on errors + check: bool, + remote: SSH | None = None, + sudo: bool = False, + **kwargs: Any, +) -> subprocess.CompletedProcess[Any]: + if sudo: + args = ["sudo"] + list(args) + if remote: + args = ["ssh", *remote.opts, remote.host, "--"] + list(args) + return subprocess.run(args, check=check, **kwargs) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py index 7af3e60846fb..6c2d261eff54 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py @@ -70,7 +70,7 @@ def test_parse_args() -> None: assert r2.attr == "bar" -@patch(get_qualified_name(nr.nix.run, nr.nix), autospec=True) +@patch(get_qualified_name(nr.process.subprocess.run), autospec=True) @patch(get_qualified_name(nr.nix.shutil.which), autospec=True, return_value="/bin/git") def test_execute_nix_boot(mock_which: Any, mock_run: Any, tmp_path: Path) -> None: nixpkgs_path = tmp_path / "nixpkgs" @@ -143,7 +143,7 @@ def test_execute_nix_boot(mock_which: Any, mock_run: Any, tmp_path: Path) -> Non ) -@patch(get_qualified_name(nr.nix.run, nr.nix), autospec=True) +@patch(get_qualified_name(nr.process.subprocess.run), autospec=True) def test_execute_nix_switch_flake(mock_run: Any, tmp_path: Path) -> None: config_path = tmp_path / "test" config_path.touch() @@ -163,6 +163,7 @@ def test_execute_nix_switch_flake(mock_run: Any, tmp_path: Path) -> None: "--flake", "/path/to/config#hostname", "--install-bootloader", + "--sudo", "--verbose", ] ) @@ -187,6 +188,7 @@ def test_execute_nix_switch_flake(mock_run: Any, tmp_path: Path) -> None: ), call( [ + "sudo", "nix-env", "-p", Path("/nix/var/nix/profiles/system"), @@ -196,7 +198,7 @@ def test_execute_nix_switch_flake(mock_run: Any, tmp_path: Path) -> None: check=True, ), call( - [config_path / "bin/switch-to-configuration", "switch"], + ["sudo", config_path / "bin/switch-to-configuration", "switch"], env={"NIXOS_INSTALL_BOOTLOADER": "1", "LOCALE_ARCHIVE": "/locale"}, check=True, ), @@ -204,7 +206,7 @@ def test_execute_nix_switch_flake(mock_run: Any, tmp_path: Path) -> None: ) -@patch(get_qualified_name(nr.nix.run, nr.nix), autospec=True) +@patch(get_qualified_name(nr.process.subprocess.run), autospec=True) def test_execute_switch_rollback(mock_run: Any, tmp_path: Path) -> None: nixpkgs_path = tmp_path / "nixpkgs" nixpkgs_path.touch() @@ -236,7 +238,7 @@ def test_execute_switch_rollback(mock_run: Any, tmp_path: Path) -> None: ) -@patch(get_qualified_name(nr.nix.run, nr.nix), autospec=True) +@patch(get_qualified_name(nr.process.subprocess.run), autospec=True) @patch(get_qualified_name(nr.nix.Path.exists, nr.nix), autospec=True, return_value=True) @patch(get_qualified_name(nr.nix.Path.mkdir, nr.nix), autospec=True) def test_execute_test_rollback( diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py index cd3a19beb789..2095607f0b03 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py @@ -3,7 +3,7 @@ from pathlib import Path from typing import Any from unittest.mock import patch -from nixos_rebuild import models as m +import nixos_rebuild.models as m from .helpers import get_qualified_name @@ -98,3 +98,12 @@ def test_profile_from_name(mock_mkdir: Any) -> None: Path("/nix/var/nix/profiles/system-profiles/something"), ) mock_mkdir.assert_called_once() + + +def test_ssh_from_name(monkeypatch: Any) -> None: + assert m.SSH.from_arg("user@localhost") == m.SSH("user@localhost", []) + + monkeypatch.setenv("SSH_OPTS", "-f foo -b bar") + assert m.SSH.from_arg("user@localhost") == m.SSH( + "user@localhost", ["-f", "foo", "-b", "bar"] + ) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py index e0468517ceca..685042c9239b 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py @@ -6,8 +6,8 @@ from unittest.mock import ANY, call, patch import pytest +import nixos_rebuild.models as m import nixos_rebuild.nix as n -from nixos_rebuild import models as m from .helpers import get_qualified_name @@ -297,10 +297,12 @@ def test_rollback_temporary_profile(tmp_path: Path) -> None: def test_set_profile(mock_run: Any) -> None: profile_path = Path("/path/to/profile") config_path = Path("/path/to/config") - n.set_profile(m.Profile("system", profile_path), config_path) + n.set_profile(m.Profile("system", profile_path), config_path, sudo=False) mock_run.assert_called_with( - ["nix-env", "-p", profile_path, "--set", config_path], check=True + ["nix-env", "-p", profile_path, "--set", config_path], + check=True, + sudo=False, ) @@ -315,6 +317,7 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: n.switch_to_configuration( profile_path, m.Action.SWITCH, + sudo=False, specialisation=None, install_bootloader=False, ) @@ -322,12 +325,14 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: [profile_path / "bin/switch-to-configuration", "switch"], env={"NIXOS_INSTALL_BOOTLOADER": "0", "LOCALE_ARCHIVE": ""}, check=True, + sudo=False, ) with pytest.raises(m.NRError) as e: n.switch_to_configuration( config_path, m.Action.BOOT, + sudo=False, specialisation="special", ) assert ( @@ -342,6 +347,7 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: n.switch_to_configuration( Path("/path/to/config"), m.Action.TEST, + sudo=True, install_bootloader=True, specialisation="special", ) @@ -352,6 +358,7 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: ], env={"NIXOS_INSTALL_BOOTLOADER": "1", "LOCALE_ARCHIVE": "/path/to/locale"}, check=True, + sudo=True, ) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py new file mode 100644 index 000000000000..8cbd0c9c9153 --- /dev/null +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py @@ -0,0 +1,47 @@ +from typing import Any +from unittest.mock import patch + +import nixos_rebuild.models as m +import nixos_rebuild.process as p + +from .helpers import get_qualified_name + + +@patch(get_qualified_name(p.subprocess.run)) +def test_run(mock_run: Any) -> None: + p.run(["test", "--with", "flags"], check=True) + mock_run.assert_called_with(["test", "--with", "flags"], check=True) + + p.run(["test", "--with", "flags"], check=False, sudo=True) + mock_run.assert_called_with(["sudo", "test", "--with", "flags"], check=False) + + p.run( + ["test", "--with", "flags"], + check=True, + remote=m.SSH("user@localhost", ["--ssh", "opt"]), + ) + mock_run.assert_called_with( + ["ssh", "--ssh", "opt", "user@localhost", "--", "test", "--with", "flags"], + check=True, + ) + + p.run( + ["test", "--with", "flags"], + check=True, + sudo=True, + remote=m.SSH("user@localhost", ["--ssh", "opt"]), + ) + mock_run.assert_called_with( + [ + "ssh", + "--ssh", + "opt", + "user@localhost", + "--", + "sudo", + "test", + "--with", + "flags", + ], + check=True, + ) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_utils.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_utils.py index bf6a404f984e..5258c7529a00 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_utils.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_utils.py @@ -1,6 +1,6 @@ import argparse -from nixos_rebuild import utils as u +import nixos_rebuild.utils as u def test_dict_to_flags() -> None: From e47b17e239c6f09ea20437ba8f3f32acfee1af17 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Sun, 17 Nov 2024 18:36:24 +0000 Subject: [PATCH 005/166] nixos-rebuild-ng: create instance for dataclass from Self --- .../src/nixos_rebuild/__init__.py | 2 -- .../src/nixos_rebuild/models.py | 24 +++++++++---------- .../nixos-rebuild-ng/src/nixos_rebuild/nix.py | 2 -- .../src/nixos_rebuild/process.py | 2 -- .../src/nixos_rebuild/utils.py | 2 -- .../ni/nixos-rebuild-ng/src/pyproject.toml | 2 -- 6 files changed, 11 insertions(+), 23 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py index fcb615eefa6e..07158b22e0e1 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py @@ -1,5 +1,3 @@ -from __future__ import annotations - import argparse import json import os diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py index 7d9082824ed8..d88faffaf019 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py @@ -1,12 +1,10 @@ -from __future__ import annotations - import os import platform import re from dataclasses import dataclass from enum import Enum from pathlib import Path -from typing import Any, ClassVar, TypedDict, override +from typing import Any, ClassVar, Self, TypedDict, override class NRError(Exception): @@ -54,15 +52,15 @@ class Flake: return f"{self.path}#{self.attr}" @classmethod - def parse(cls, flake_str: str, hostname: str | None = None) -> Flake: + def parse(cls, flake_str: str, hostname: str | None = None) -> Self: m = cls._re.match(flake_str) assert m is not None, f"got no matches for {flake_str}" attr = m.group("attr") nixos_attr = f"nixosConfigurations.{attr or hostname or "default"}" - return Flake(Path(m.group("path")), nixos_attr) + return cls(Path(m.group("path")), nixos_attr) @classmethod - def from_arg(cls, flake_arg: Any) -> Flake | None: + def from_arg(cls, flake_arg: Any) -> Self | None: hostname = platform.node() match flake_arg: case str(s): @@ -106,15 +104,15 @@ class Profile: name: str path: Path - @staticmethod - def from_name(name: str = "system") -> Profile: + @classmethod + def from_name(cls, name: str = "system") -> Self: match name: case "system": - return Profile(name, Path("/nix/var/nix/profiles/system")) + return cls(name, Path("/nix/var/nix/profiles/system")) case _: path = Path("/nix/var/nix/profiles/system-profiles") / name path.parent.mkdir(mode=0o755, parents=True, exist_ok=True) - return Profile(name, path) + return cls(name, path) @dataclass(frozen=True) @@ -122,10 +120,10 @@ class SSH: host: str opts: list[str] - @staticmethod - def from_arg(host: str | None) -> SSH | None: + @classmethod + def from_arg(cls, host: str | None) -> Self | None: if host: opts = os.getenv("SSH_OPTS", "").split() - return SSH(host, opts) + return cls(host, opts) else: return None diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py index bedd6a265879..3f1f81cb6257 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py @@ -1,5 +1,3 @@ -from __future__ import annotations - import os import shutil from datetime import datetime diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py index 95a962904d68..123acf3e60e6 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py @@ -1,5 +1,3 @@ -from __future__ import annotations - import os import subprocess from typing import Any, Sequence diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/utils.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/utils.py index 704688a3a3c7..6c96358441e1 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/utils.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/utils.py @@ -1,5 +1,3 @@ -from __future__ import annotations - import argparse import sys from functools import partial diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/pyproject.toml b/pkgs/by-name/ni/nixos-rebuild-ng/src/pyproject.toml index 457bcfe011b6..e70719c1c4fe 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/pyproject.toml +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/pyproject.toml @@ -38,8 +38,6 @@ ignore_missing_imports = true extend-select = [ # ensure imports are sorted "I", - # require 'from __future__ import annotations' - "FA102", # require `check` argument for `subprocess.run` "PLW1510", ] From 31e9e8c0aa0b5a2c83df8446c73af5a24052707d Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Sun, 17 Nov 2024 19:10:03 +0000 Subject: [PATCH 006/166] nixos-rebuild-ng: run -> run_wrapper, handle encode errors and add extra_env --- .../nixos-rebuild-ng/src/nixos_rebuild/nix.py | 47 +++++++------- .../src/nixos_rebuild/process.py | 54 +++++++++++---- .../nixos-rebuild-ng/src/tests/test_main.py | 33 +++++----- .../ni/nixos-rebuild-ng/src/tests/test_nix.py | 40 +++++------- .../src/tests/test_process.py | 65 +++++++++++++++++-- 5 files changed, 159 insertions(+), 80 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py index 3f1f81cb6257..dbc3b84bd8c4 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py @@ -13,7 +13,7 @@ from .models import ( NRError, Profile, ) -from .process import run +from .process import run_wrapper from .utils import Args, dict_to_flags, info FLAKE_FLAGS: Final = ["--extra-experimental-features", "nix-command flakes"] @@ -22,7 +22,7 @@ FLAKE_FLAGS: Final = ["--extra-experimental-features", "nix-command flakes"] def edit(flake: Flake | None, **flake_flags: Args) -> None: "Try to find and open NixOS configuration file in editor." if flake: - run( + run_wrapper( [ "nix", *FLAKE_FLAGS, @@ -38,9 +38,8 @@ def edit(flake: Flake | None, **flake_flags: Args) -> None: raise NRError("'edit' does not support extra Nix flags") nixos_config = Path( os.getenv("NIXOS_CONFIG") - or run( + or run_wrapper( ["nix-instantiate", "--find-file", "nixos-config"], - text=True, stdout=PIPE, check=False, ).stdout.strip() @@ -50,18 +49,17 @@ def edit(flake: Flake | None, **flake_flags: Args) -> None: nixos_config /= "default.nix" if nixos_config.exists(): - run([os.getenv("EDITOR", "nano"), nixos_config], check=False) + run_wrapper([os.getenv("EDITOR", "nano"), nixos_config], check=False) else: raise NRError("cannot find NixOS config file") def find_file(file: str, **nix_flags: Args) -> Path | None: "Find classic Nixpkgs location." - r = run( + r = run_wrapper( ["nix-instantiate", "--find-file", file, *dict_to_flags(nix_flags)], stdout=PIPE, check=False, - text=True, ) if r.returncode: return None @@ -81,17 +79,19 @@ def get_nixpkgs_rev(nixpkgs_path: Path | None) -> str | None: return None # Get current revision - r = run( + r = run_wrapper( ["git", "-C", nixpkgs_path, "rev-parse", "--short", "HEAD"], check=False, stdout=PIPE, - text=True, ) rev = r.stdout.strip() if rev: # Check if repo is dirty - if run(["git", "-C", nixpkgs_path, "diff", "--quiet"], check=False).returncode: + if run_wrapper( + ["git", "-C", nixpkgs_path, "diff", "--quiet"], + check=False, + ).returncode: rev += "M" return f".git.{rev}" else: @@ -142,10 +142,9 @@ def get_generations(profile: Profile, lock_profile: bool = False) -> list[Genera # Using `nix-env --list-generations` needs root to lock the profile # TODO: do we actually need to lock profile for e.g.: rollback? # https://github.com/NixOS/nix/issues/5144 - r = run( + r = run_wrapper( ["nix-env", "-p", profile.path, "--list-generations"], - text=True, - stdout=True, + stdout=PIPE, check=True, ) for line in r.stdout.splitlines(): @@ -185,11 +184,10 @@ def list_generations(profile: Profile) -> list[GenerationJson]: s.name for s in (generation_path / "specialisation").glob("*") if s.is_dir() ] try: - configuration_revision = run( + configuration_revision = run_wrapper( [generation_path / "sw/bin/nixos-version", "--configuration-revision"], capture_output=True, check=True, - text=True, ).stdout.strip() except (CalledProcessError, IOError): configuration_revision = "Unknown" @@ -233,7 +231,7 @@ def nixos_build( else: run_args = ["nix-build", "", "--attr", attr] run_args += dict_to_flags(nix_flags) - r = run(run_args, check=True, text=True, stdout=PIPE) + r = run_wrapper(run_args, check=True, stdout=PIPE) return Path(r.stdout.strip()) @@ -254,13 +252,13 @@ def nixos_build_flake( f"{flake}.config.system.build.{attr}", ] run_args += dict_to_flags(flake_flags) - r = run(run_args, check=True, text=True, stdout=PIPE) + r = run_wrapper(run_args, check=True, stdout=PIPE) return Path(r.stdout.strip()) def rollback(profile: Profile) -> Path: "Rollback Nix profile, like one created by `nixos-rebuild switch`." - run(["nix-env", "--rollback", "-p", profile.path], check=True) + run_wrapper(["nix-env", "--rollback", "-p", profile.path], check=True) # Rollback config PATH is the own profile return profile.path @@ -281,7 +279,9 @@ def rollback_temporary_profile(profile: Profile) -> Path | None: def set_profile(profile: Profile, path_to_config: Path, sudo: bool) -> None: "Set a path as the current active Nix profile." - run(["nix-env", "-p", profile.path, "--set", path_to_config], check=True, sudo=sudo) + run_wrapper( + ["nix-env", "-p", profile.path, "--set", path_to_config], check=True, sudo=sudo + ) def switch_to_configuration( @@ -306,12 +306,9 @@ def switch_to_configuration( if not path_to_config.exists(): raise NRError(f"specialisation not found: {specialisation}") - run( + run_wrapper( [path_to_config / "bin/switch-to-configuration", str(action)], - env={ - "NIXOS_INSTALL_BOOTLOADER": "1" if install_bootloader else "0", - "LOCALE_ARCHIVE": os.getenv("LOCALE_ARCHIVE", ""), - }, + extra_env={"NIXOS_INSTALL_BOOTLOADER": "1" if install_bootloader else "0"}, check=True, sudo=sudo, ) @@ -329,4 +326,4 @@ def upgrade_channels(all: bool = False) -> None: or channel_path.name == "nixos" or (channel_path / ".update-on-nixos-rebuild").exists() ): - run(["nix-channel", "--update", channel_path.name], check=False) + run_wrapper(["nix-channel", "--update", channel_path.name], check=False) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py index 123acf3e60e6..8ae25b5e767a 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py @@ -1,20 +1,52 @@ +from __future__ import annotations + import os import subprocess -from typing import Any, Sequence +from typing import Sequence, TypedDict, Unpack from .models import SSH -def run( - args: Sequence[str | bytes | os.PathLike[Any]], - # make `check` explicit so we always know if the code is aborting on errors - check: bool, +# Not exhaustive, but we can always extend it later. +class RunKwargs(TypedDict, total=False): + capture_output: bool + stderr: int | None + stdin: int | None + stdout: int | None + + +def run_wrapper( + args: Sequence[str | bytes | os.PathLike[str] | os.PathLike[bytes]], + *, + check: bool, # make it explicit so we always know if the code is handling errors + env: dict[str, str] | None = None, # replaces the current environment + extra_env: dict[str, str] | None = None, # appends to the current environment remote: SSH | None = None, sudo: bool = False, - **kwargs: Any, -) -> subprocess.CompletedProcess[Any]: - if sudo: - args = ["sudo"] + list(args) + **kwargs: Unpack[RunKwargs], +) -> subprocess.CompletedProcess[str]: + "Wrapper around `subprocess.run` that supports extra functionality." if remote: - args = ["ssh", *remote.opts, remote.host, "--"] + list(args) - return subprocess.run(args, check=check, **kwargs) + assert env is None, "'env' can't be used with 'remote'" + if extra_env: + extra_env_args = [f"{env}={value}" for env, value in extra_env.items()] + args = ["env", *extra_env_args, *args] + if sudo: + args = ["sudo", *args] + args = ["ssh", *remote.opts, remote.host, "--", *args] + else: + if extra_env: + env = (env or os.environ) | extra_env + if sudo: + args = ["sudo", *args] + + return subprocess.run( + args, + check=check, + env=env, + # Hope nobody is using NixOS with non-UTF8 encodings, but "surrogateescape" + # should still work in those systems. + text=True, + errors="surrogateescape", + **kwargs, + ) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py index 6c2d261eff54..e5a657c886ae 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py @@ -2,7 +2,7 @@ import textwrap from pathlib import Path from subprocess import PIPE, CompletedProcess from typing import Any -from unittest.mock import call, patch +from unittest.mock import ANY, call, patch import pytest @@ -10,10 +10,7 @@ import nixos_rebuild as nr from .helpers import get_qualified_name - -@pytest.fixture(autouse=True) -def setup(monkeypatch: Any) -> None: - monkeypatch.setenv("LOCALE_ARCHIVE", "/locale") +DEFAULT_RUN_KWARGS = {"text": True, "errors": "surrogateescape", "env": ANY} def test_parse_args() -> None: @@ -70,6 +67,7 @@ def test_parse_args() -> None: assert r2.attr == "bar" +@patch.dict(nr.process.os.environ, {}, clear=True) @patch(get_qualified_name(nr.process.subprocess.run), autospec=True) @patch(get_qualified_name(nr.nix.shutil.which), autospec=True, return_value="/bin/git") def test_execute_nix_boot(mock_which: Any, mock_run: Any, tmp_path: Path) -> None: @@ -99,17 +97,18 @@ def test_execute_nix_boot(mock_which: Any, mock_run: Any, tmp_path: Path) -> Non ["nix-instantiate", "--find-file", "nixpkgs", "-vvv"], stdout=PIPE, check=False, - text=True, + **DEFAULT_RUN_KWARGS, ), call( ["git", "-C", nixpkgs_path, "rev-parse", "--short", "HEAD"], check=False, stdout=PIPE, - text=True, + **DEFAULT_RUN_KWARGS, ), call( ["git", "-C", nixpkgs_path, "diff", "--quiet"], check=False, + **DEFAULT_RUN_KWARGS, ), call( [ @@ -121,8 +120,8 @@ def test_execute_nix_boot(mock_which: Any, mock_run: Any, tmp_path: Path) -> Non "-vvv", ], check=True, - text=True, stdout=PIPE, + **DEFAULT_RUN_KWARGS, ), call( [ @@ -133,16 +132,18 @@ def test_execute_nix_boot(mock_which: Any, mock_run: Any, tmp_path: Path) -> Non config_path, ], check=True, + **DEFAULT_RUN_KWARGS, ), call( [config_path / "bin/switch-to-configuration", "boot"], - env={"NIXOS_INSTALL_BOOTLOADER": "0", "LOCALE_ARCHIVE": "/locale"}, check=True, + **(DEFAULT_RUN_KWARGS | {"env": {"NIXOS_INSTALL_BOOTLOADER": "0"}}), ), ] ) +@patch.dict(nr.process.os.environ, {}, clear=True) @patch(get_qualified_name(nr.process.subprocess.run), autospec=True) def test_execute_nix_switch_flake(mock_run: Any, tmp_path: Path) -> None: config_path = tmp_path / "test" @@ -183,8 +184,8 @@ def test_execute_nix_switch_flake(mock_run: Any, tmp_path: Path) -> None: "-v", ], check=True, - text=True, stdout=PIPE, + **DEFAULT_RUN_KWARGS, ), call( [ @@ -196,11 +197,12 @@ def test_execute_nix_switch_flake(mock_run: Any, tmp_path: Path) -> None: config_path, ], check=True, + **DEFAULT_RUN_KWARGS, ), call( ["sudo", config_path / "bin/switch-to-configuration", "switch"], - env={"NIXOS_INSTALL_BOOTLOADER": "1", "LOCALE_ARCHIVE": "/locale"}, check=True, + **(DEFAULT_RUN_KWARGS | {"env": {"NIXOS_INSTALL_BOOTLOADER": "1"}}), ), ] ) @@ -225,14 +227,15 @@ def test_execute_switch_rollback(mock_run: Any, tmp_path: Path) -> None: Path("/nix/var/nix/profiles/system"), ], check=True, + **DEFAULT_RUN_KWARGS, ), call( [ Path("/nix/var/nix/profiles/system/bin/switch-to-configuration"), "switch", ], - env={"NIXOS_INSTALL_BOOTLOADER": "1", "LOCALE_ARCHIVE": "/locale"}, check=True, + **DEFAULT_RUN_KWARGS, ), ] ) @@ -281,9 +284,9 @@ def test_execute_test_rollback( Path("/nix/var/nix/profiles/system-profiles/foo"), "--list-generations", ], - text=True, - stdout=True, check=True, + stdout=PIPE, + **DEFAULT_RUN_KWARGS, ), call( [ @@ -292,8 +295,8 @@ def test_execute_test_rollback( ), "test", ], - env={"NIXOS_INSTALL_BOOTLOADER": "0", "LOCALE_ARCHIVE": "/locale"}, check=True, + **DEFAULT_RUN_KWARGS, ), ] ) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py index 685042c9239b..46b89bc355ba 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py @@ -12,7 +12,7 @@ import nixos_rebuild.nix as n from .helpers import get_qualified_name -@patch(get_qualified_name(n.run, n), autospec=True) +@patch(get_qualified_name(n.run_wrapper, n), autospec=True) def test_edit(mock_run: Any, monkeypatch: Any, tmpdir: Any) -> None: # Flake flake = m.Flake.parse(".#attr") @@ -49,7 +49,7 @@ def test_get_nixpkgs_rev(mock_which: Any) -> None: path = Path("/path/to/nix") with patch( - get_qualified_name(n.run, n), + get_qualified_name(n.run_wrapper, n), autospec=True, side_effect=[CompletedProcess([], 0, "")], ) as mock_run: @@ -58,7 +58,6 @@ def test_get_nixpkgs_rev(mock_which: Any) -> None: ["git", "-C", path, "rev-parse", "--short", "HEAD"], check=False, stdout=PIPE, - text=True, ) expected_calls = [ @@ -66,7 +65,6 @@ def test_get_nixpkgs_rev(mock_which: Any) -> None: ["git", "-C", path, "rev-parse", "--short", "HEAD"], check=False, stdout=PIPE, - text=True, ), call( ["git", "-C", path, "diff", "--quiet"], @@ -75,7 +73,7 @@ def test_get_nixpkgs_rev(mock_which: Any) -> None: ] with patch( - get_qualified_name(n.run, n), + get_qualified_name(n.run_wrapper, n), autospec=True, side_effect=[ CompletedProcess([], 0, "0f7c82403fd6"), @@ -86,7 +84,7 @@ def test_get_nixpkgs_rev(mock_which: Any) -> None: mock_run.assert_has_calls(expected_calls) with patch( - get_qualified_name(n.run, n), + get_qualified_name(n.run_wrapper, n), autospec=True, side_effect=[ CompletedProcess([], 0, "0f7c82403fd6"), @@ -118,7 +116,7 @@ def test_get_generations_from_nix_store(tmp_path: Path) -> None: @patch( - get_qualified_name(n.run, n), + get_qualified_name(n.run_wrapper, n), autospec=True, return_value=CompletedProcess( [], @@ -183,7 +181,7 @@ def test_list_generations(mock_get_generations: Any, tmp_path: Path) -> None: @patch( - get_qualified_name(n.run, n), + get_qualified_name(n.run_wrapper, n), autospec=True, return_value=CompletedProcess([], 0, stdout=" \n/path/to/file\n "), ) @@ -209,13 +207,12 @@ def test_nixos_build_flake(mock_run: Any) -> None: "foo", ], check=True, - text=True, stdout=PIPE, ) @patch( - get_qualified_name(n.run, n), + get_qualified_name(n.run_wrapper, n), autospec=True, return_value=CompletedProcess([], 0, stdout=" \n/path/to/file\n "), ) @@ -224,7 +221,6 @@ def test_nixos_build(mock_run: Any, monkeypatch: Any) -> None: mock_run.assert_called_with( ["nix-build", "", "--attr", "attr", "--nix-flag", "foo"], check=True, - text=True, stdout=PIPE, ) @@ -232,7 +228,6 @@ def test_nixos_build(mock_run: Any, monkeypatch: Any) -> None: mock_run.assert_called_with( ["nix-build", "file", "--attr", "preAttr.attr"], check=True, - text=True, stdout=PIPE, ) @@ -240,7 +235,6 @@ def test_nixos_build(mock_run: Any, monkeypatch: Any) -> None: mock_run.assert_called_with( ["nix-build", "file", "--attr", "attr", "--no-out-link"], check=True, - text=True, stdout=PIPE, ) @@ -248,12 +242,11 @@ def test_nixos_build(mock_run: Any, monkeypatch: Any) -> None: mock_run.assert_called_with( ["nix-build", "default.nix", "--attr", "preAttr.attr", "--keep-going"], check=True, - text=True, stdout=PIPE, ) -@patch(get_qualified_name(n.run, n), autospec=True) +@patch(get_qualified_name(n.run_wrapper, n), autospec=True) def test_rollback(mock_run: Any, tmp_path: Path) -> None: path = tmp_path / "test" path.touch() @@ -269,7 +262,7 @@ def test_rollback_temporary_profile(tmp_path: Path) -> None: path.touch() profile = m.Profile("system", path) - with patch(get_qualified_name(n.run, n), autospec=True) as mock_run: + with patch(get_qualified_name(n.run_wrapper, n), autospec=True) as mock_run: mock_run.return_value = CompletedProcess( [], 0, @@ -288,12 +281,12 @@ def test_rollback_temporary_profile(tmp_path: Path) -> None: == path.parent / "foo-2083-link" ) - with patch(get_qualified_name(n.run, n), autospec=True) as mock_run: + with patch(get_qualified_name(n.run_wrapper, n), autospec=True) as mock_run: mock_run.return_value = CompletedProcess([], 0, stdout="") assert n.rollback_temporary_profile(profile) is None -@patch(get_qualified_name(n.run, n), autospec=True) +@patch(get_qualified_name(n.run_wrapper, n), autospec=True) def test_set_profile(mock_run: Any) -> None: profile_path = Path("/path/to/profile") config_path = Path("/path/to/config") @@ -306,7 +299,7 @@ def test_set_profile(mock_run: Any) -> None: ) -@patch(get_qualified_name(n.run, n), autospec=True) +@patch(get_qualified_name(n.run_wrapper, n), autospec=True) def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: profile_path = Path("/path/to/profile") config_path = Path("/path/to/config") @@ -323,7 +316,7 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: ) mock_run.assert_called_with( [profile_path / "bin/switch-to-configuration", "switch"], - env={"NIXOS_INSTALL_BOOTLOADER": "0", "LOCALE_ARCHIVE": ""}, + extra_env={"NIXOS_INSTALL_BOOTLOADER": "0"}, check=True, sudo=False, ) @@ -342,6 +335,7 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: with monkeypatch.context() as mp: mp.setenv("LOCALE_ARCHIVE", "/path/to/locale") + mp.setenv("PATH", "/path/to/bin") mp.setattr(Path, Path.exists.__name__, lambda self: True) n.switch_to_configuration( @@ -356,7 +350,7 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: config_path / "specialisation/special/bin/switch-to-configuration", "test", ], - env={"NIXOS_INSTALL_BOOTLOADER": "1", "LOCALE_ARCHIVE": "/path/to/locale"}, + extra_env={"NIXOS_INSTALL_BOOTLOADER": "1"}, check=True, sudo=True, ) @@ -372,11 +366,11 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: ], ) def test_upgrade_channels(mock_glob: Any) -> None: - with patch(get_qualified_name(n.run, n), autospec=True) as mock_run: + with patch(get_qualified_name(n.run_wrapper, n), autospec=True) as mock_run: n.upgrade_channels(False) mock_run.assert_called_with(["nix-channel", "--update", "nixos"], check=False) - with patch(get_qualified_name(n.run, n), autospec=True) as mock_run: + with patch(get_qualified_name(n.run_wrapper, n), autospec=True) as mock_run: n.upgrade_channels(True) mock_run.assert_has_calls( [ diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py index 8cbd0c9c9153..e0d516480711 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py @@ -1,6 +1,8 @@ from typing import Any from unittest.mock import patch +import pytest + import nixos_rebuild.models as m import nixos_rebuild.process as p @@ -9,13 +11,34 @@ from .helpers import get_qualified_name @patch(get_qualified_name(p.subprocess.run)) def test_run(mock_run: Any) -> None: - p.run(["test", "--with", "flags"], check=True) - mock_run.assert_called_with(["test", "--with", "flags"], check=True) + p.run_wrapper(["test", "--with", "flags"], check=True) + mock_run.assert_called_with( + ["test", "--with", "flags"], + check=True, + text=True, + errors="surrogateescape", + env=None, + ) - p.run(["test", "--with", "flags"], check=False, sudo=True) - mock_run.assert_called_with(["sudo", "test", "--with", "flags"], check=False) + with patch.dict(p.os.environ, {"PATH": "/path/to/bin"}, clear=True): + p.run_wrapper( + ["test", "--with", "flags"], + check=False, + sudo=True, + extra_env={"FOO": "bar"}, + ) + mock_run.assert_called_with( + ["sudo", "test", "--with", "flags"], + check=False, + text=True, + errors="surrogateescape", + env={ + "PATH": "/path/to/bin", + "FOO": "bar", + }, + ) - p.run( + p.run_wrapper( ["test", "--with", "flags"], check=True, remote=m.SSH("user@localhost", ["--ssh", "opt"]), @@ -23,12 +46,29 @@ def test_run(mock_run: Any) -> None: mock_run.assert_called_with( ["ssh", "--ssh", "opt", "user@localhost", "--", "test", "--with", "flags"], check=True, + text=True, + errors="surrogateescape", + env=None, ) - p.run( + p.run_wrapper( + ["test", "--with", "flags"], + check=False, + env={"FOO": "bar"}, + ) + mock_run.assert_called_with( + ["test", "--with", "flags"], + check=False, + env={"FOO": "bar"}, + text=True, + errors="surrogateescape", + ) + + p.run_wrapper( ["test", "--with", "flags"], check=True, sudo=True, + extra_env={"FOO": "bar"}, remote=m.SSH("user@localhost", ["--ssh", "opt"]), ) mock_run.assert_called_with( @@ -39,9 +79,22 @@ def test_run(mock_run: Any) -> None: "user@localhost", "--", "sudo", + "env", + "FOO=bar", "test", "--with", "flags", ], check=True, + env=None, + text=True, + errors="surrogateescape", ) + + with pytest.raises(AssertionError): + p.run_wrapper( + ["test", "--with", "flags"], + check=False, + env={"foo": "bar"}, + remote=m.SSH("user@localhost", []), + ) From a6b9aaba1b11ea22522113dc5058be6dc3615571 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Wed, 20 Nov 2024 10:41:09 +0000 Subject: [PATCH 007/166] nixos-rebuild-ng: add TTY allocation in SSH --- .../ni/nixos-rebuild-ng/src/nixos_rebuild/models.py | 5 +++-- .../ni/nixos-rebuild-ng/src/nixos_rebuild/process.py | 6 +++++- pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py | 8 +++++--- .../by-name/ni/nixos-rebuild-ng/src/tests/test_process.py | 7 ++++--- 4 files changed, 17 insertions(+), 9 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py index d88faffaf019..5ee8d411ab0c 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py @@ -119,11 +119,12 @@ class Profile: class SSH: host: str opts: list[str] + tty: bool @classmethod - def from_arg(cls, host: str | None) -> Self | None: + def from_arg(cls, host: str | None, tty: bool | None) -> Self | None: if host: opts = os.getenv("SSH_OPTS", "").split() - return cls(host, opts) + return cls(host, opts, bool(tty)) else: return None diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py index 8ae25b5e767a..ef08673393a7 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py @@ -10,6 +10,7 @@ from .models import SSH # Not exhaustive, but we can always extend it later. class RunKwargs(TypedDict, total=False): capture_output: bool + input: str | None stderr: int | None stdin: int | None stdout: int | None @@ -33,7 +34,10 @@ def run_wrapper( args = ["env", *extra_env_args, *args] if sudo: args = ["sudo", *args] - args = ["ssh", *remote.opts, remote.host, "--", *args] + if remote.tty: + args = ["ssh", "-t", *remote.opts, remote.host, "--", *args] + else: + args = ["ssh", *remote.opts, remote.host, "--", *args] else: if extra_env: env = (env or os.environ) | extra_env diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py index 2095607f0b03..63cddc479f43 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py @@ -101,9 +101,11 @@ def test_profile_from_name(mock_mkdir: Any) -> None: def test_ssh_from_name(monkeypatch: Any) -> None: - assert m.SSH.from_arg("user@localhost") == m.SSH("user@localhost", []) + assert m.SSH.from_arg("user@localhost", None) == m.SSH("user@localhost", [], False) monkeypatch.setenv("SSH_OPTS", "-f foo -b bar") - assert m.SSH.from_arg("user@localhost") == m.SSH( - "user@localhost", ["-f", "foo", "-b", "bar"] + assert m.SSH.from_arg("user@localhost", True) == m.SSH( + "user@localhost", + ["-f", "foo", "-b", "bar"], + True, ) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py index e0d516480711..19a56581b6fd 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py @@ -41,7 +41,7 @@ def test_run(mock_run: Any) -> None: p.run_wrapper( ["test", "--with", "flags"], check=True, - remote=m.SSH("user@localhost", ["--ssh", "opt"]), + remote=m.SSH("user@localhost", ["--ssh", "opt"], False), ) mock_run.assert_called_with( ["ssh", "--ssh", "opt", "user@localhost", "--", "test", "--with", "flags"], @@ -69,11 +69,12 @@ def test_run(mock_run: Any) -> None: check=True, sudo=True, extra_env={"FOO": "bar"}, - remote=m.SSH("user@localhost", ["--ssh", "opt"]), + remote=m.SSH("user@localhost", ["--ssh", "opt"], True), ) mock_run.assert_called_with( [ "ssh", + "-t", "--ssh", "opt", "user@localhost", @@ -96,5 +97,5 @@ def test_run(mock_run: Any) -> None: ["test", "--with", "flags"], check=False, env={"foo": "bar"}, - remote=m.SSH("user@localhost", []), + remote=m.SSH("user@localhost", [], False), ) From 3d7fbe88ab4f20996c2124e0d054d15af27eaa3f Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Wed, 20 Nov 2024 18:30:49 +0000 Subject: [PATCH 008/166] nixos-rebuild-ng: parse NIX_SSHOPTS instead of SSH_OPTS env var --- .../src/nixos_rebuild/models.py | 11 ++++-- .../nixos-rebuild-ng/src/tests/test_models.py | 34 +++++++++++++++---- 2 files changed, 37 insertions(+), 8 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py index 5ee8d411ab0c..6c9f01a115f0 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py @@ -122,9 +122,16 @@ class SSH: tty: bool @classmethod - def from_arg(cls, host: str | None, tty: bool | None) -> Self | None: + def from_arg(cls, host: str | None, tty: bool | None, tmp_dir: Path) -> Self | None: if host: - opts = os.getenv("SSH_OPTS", "").split() + opts = os.getenv("NIX_SSHOPTS", "").split() + [ + "-o", + "ControlMaster=auto", + "-o", + f"ControlPath={tmp_dir / "ssh-%n"}", + "-o", + "ControlPersist=60", + ] return cls(host, opts, bool(tty)) else: return None diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py index 63cddc479f43..d2c0442b4369 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py @@ -100,12 +100,34 @@ def test_profile_from_name(mock_mkdir: Any) -> None: mock_mkdir.assert_called_once() -def test_ssh_from_name(monkeypatch: Any) -> None: - assert m.SSH.from_arg("user@localhost", None) == m.SSH("user@localhost", [], False) - - monkeypatch.setenv("SSH_OPTS", "-f foo -b bar") - assert m.SSH.from_arg("user@localhost", True) == m.SSH( +def test_ssh_from_name(monkeypatch: Any, tmpdir: Path) -> None: + assert m.SSH.from_arg("user@localhost", None, tmpdir) == m.SSH( "user@localhost", - ["-f", "foo", "-b", "bar"], + [ + "-o", + "ControlMaster=auto", + "-o", + f"ControlPath={tmpdir / "ssh-%n"}", + "-o", + "ControlPersist=60", + ], + False, + ) + + monkeypatch.setenv("NIX_SSHOPTS", "-f foo -b bar", tmpdir) + assert m.SSH.from_arg("user@localhost", True, tmpdir) == m.SSH( + "user@localhost", + [ + "-f", + "foo", + "-b", + "bar", + "-o", + "ControlMaster=auto", + "-o", + f"ControlPath={tmpdir / "ssh-%n"}", + "-o", + "ControlPersist=60", + ], True, ) From fd1cd69315b92f95f574f1a33c13cb00a463e01a Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Sun, 24 Nov 2024 02:03:54 +0000 Subject: [PATCH 009/166] nixos-rebuild-ng: add pythonpath to pytest config --- pkgs/by-name/ni/nixos-rebuild-ng/README.md | 2 +- pkgs/by-name/ni/nixos-rebuild-ng/src/pyproject.toml | 1 + 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/README.md b/pkgs/by-name/ni/nixos-rebuild-ng/README.md index d74eda27cdf4..a6199e873060 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/README.md +++ b/pkgs/by-name/ni/nixos-rebuild-ng/README.md @@ -76,7 +76,7 @@ can run: # run program python -m nixos_rebuild # run tests -python -m pytest +pytest # check types mypy . # fix lint issues diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/pyproject.toml b/pkgs/by-name/ni/nixos-rebuild-ng/src/pyproject.toml index e70719c1c4fe..f26b3cba7056 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/pyproject.toml +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/pyproject.toml @@ -46,4 +46,5 @@ extend-select = [ "tests/" = ["FA102"] [tool.pytest.ini_options] +pythonpath = ["."] addopts = ["--import-mode=importlib"] From a2cbe67701fe4b3614505e219dc4c645e5df0e61 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Fri, 22 Nov 2024 19:10:37 +0000 Subject: [PATCH 010/166] nixos-rebuild-ng: implement `--target-host` --- .../src/nixos_rebuild/__init__.py | 105 +++++++++++------- .../src/nixos_rebuild/models.py | 2 +- .../nixos-rebuild-ng/src/nixos_rebuild/nix.py | 37 +++++- .../src/nixos_rebuild/process.py | 4 +- .../nixos-rebuild-ng/src/tests/test_main.py | 103 +++++++++++++++++ .../nixos-rebuild-ng/src/tests/test_models.py | 7 +- .../ni/nixos-rebuild-ng/src/tests/test_nix.py | 28 ++++- .../src/tests/test_process.py | 6 +- 8 files changed, 242 insertions(+), 50 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py index 07158b22e0e1..7215bc05725f 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py @@ -2,11 +2,14 @@ import argparse import json import os import sys +from pathlib import Path from subprocess import run +from tempfile import TemporaryDirectory from typing import assert_never -from .models import Action, Flake, NRError, Profile +from .models import Action, Flake, NRError, Profile, Ssh from .nix import ( + copy_closure, edit, find_file, get_nixpkgs_rev, @@ -37,8 +40,7 @@ def parse_args(argv: list[str]) -> argparse.Namespace: parser.add_argument("--flake", nargs="?", const=True) parser.add_argument("--no-flake", dest="flake", action="store_false") parser.add_argument("--install-bootloader", action="store_true") - # TODO: add deprecated=True in Python >=3.13 - parser.add_argument("--install-grub", action="store_true") + parser.add_argument("--install-grub", action="store_true") # deprecated parser.add_argument("--profile-name", "-p", default="system") parser.add_argument("--specialisation", "-c") parser.add_argument("--rollback", action="store_true") @@ -46,12 +48,14 @@ def parse_args(argv: list[str]) -> argparse.Namespace: parser.add_argument("--upgrade-all", action="store_true") parser.add_argument("--json", action="store_true") parser.add_argument("--sudo", action="store_true") - # TODO: add deprecated=True in Python >=3.13 - parser.add_argument("--use-remote-sudo", dest="sudo", action="store_true") - parser.add_argument("action", choices=Action.values(), nargs="?") + parser.add_argument("--use-remote-sudo", action="store_true") # deprecated + parser.add_argument("--no-ssh-tty", action="store_true") + # parser.add_argument("--build-host") # TODO + parser.add_argument("--target-host") parser.add_argument("--verbose", "-v", action="count", default=0) + parser.add_argument("action", choices=Action.values(), nargs="?") - common_group = parser.add_argument_group("Common flags") + common_group = parser.add_argument_group("nix flags") common_group.add_argument("--include", "-I") common_group.add_argument("--max-jobs", "-j") common_group.add_argument("--cores") @@ -65,10 +69,10 @@ def parse_args(argv: list[str]) -> argparse.Namespace: common_group.add_argument("--repair", action="store_true") common_group.add_argument("--option", nargs=2) - nix_group = parser.add_argument_group("Classic Nix flags") + nix_group = parser.add_argument_group("nix classic flags") nix_group.add_argument("--no-build-output", "-Q", action="store_true") - flake_group = parser.add_argument_group("Flake flags") + flake_group = parser.add_argument_group("nix flakes flags") flake_group.add_argument("--accept-flake-config", action="store_true") flake_group.add_argument("--refresh", action="store_true") flake_group.add_argument("--impure", action="store_true") @@ -82,6 +86,9 @@ def parse_args(argv: list[str]) -> argparse.Namespace: flake_group.add_argument("--update-input") flake_group.add_argument("--override-input", nargs=2) + copy_group = parser.add_argument_group("nix-copy-closure flags") + copy_group.add_argument("--use-substitutes", "-s", action="store_true") + args = parser.parse_args(argv[1:]) global VERBOSE @@ -92,12 +99,20 @@ def parse_args(argv: list[str]) -> argparse.Namespace: if args.action == Action.DRY_RUN.value: args.action = Action.DRY_BUILD.value + # TODO: use deprecated=True in Python >=3.13 if args.install_grub: info( f"{parser.prog}: warning: --install-grub deprecated, use --install-bootloader instead" ) args.install_bootloader = True + # TODO: use deprecated=True in Python >=3.13 + if args.use_remote_sudo: + info( + f"{parser.prog}: warning: --use-remote-sudo deprecated, use --sudo instead" + ) + args.sudo = True + if args.action == Action.EDIT.value and (args.file or args.attr): parser.error("--file and --attr are not supported with 'edit'") @@ -117,23 +132,28 @@ def execute(argv: list[str]) -> None: common_flags = flags_to_dict( args, [ - "verbose", - "include", "max_jobs", "cores", "log_format", - "quiet", - "print_build_logs", - "show_trace", "keep_going", "keep_failed", "fallback", "repair", + "verbose", "option", ], ) - nix_flags = common_flags | flags_to_dict(args, ["no_build_output"]) - flake_flags = common_flags | flags_to_dict( + common_build_flags = common_flags | flags_to_dict( + args, + [ + "include", + "quiet", + "print_build_logs", + "show_trace", + ], + ) + build_flags = common_build_flags | flags_to_dict(args, ["no_build_output"]) + flake_build_flags = common_build_flags | flags_to_dict( args, [ "accept_flake_config", @@ -150,9 +170,15 @@ def execute(argv: list[str]) -> None: "override_input", ], ) + copy_flags = common_flags | flags_to_dict(args, ["use_substitutes"]) + + # Will be cleaned up on exit automatically. + tmpdir = TemporaryDirectory(prefix="nixos-rebuild.") + tmpdir_path = Path(tmpdir.name) profile = Profile.from_name(args.profile_name) flake = Flake.from_arg(args.flake) + target_host = Ssh.from_arg(args.target_host, not args.no_ssh_tty, tmpdir_path) if args.upgrade or args.upgrade_all: upgrade_channels(bool(args.upgrade_all)) @@ -165,7 +191,7 @@ def execute(argv: list[str]) -> None: # untrusted tree. can_run = action in (Action.SWITCH, Action.BOOT, Action.TEST) if can_run and not flake: - nixpkgs_path = find_file("nixpkgs", **nix_flags) + nixpkgs_path = find_file("nixpkgs", **build_flags) rev = get_nixpkgs_rev(nixpkgs_path) if nixpkgs_path and rev: (nixpkgs_path / ".version-suffix").write_text(rev) @@ -175,26 +201,28 @@ def execute(argv: list[str]) -> None: info("building the system configuration...") if args.rollback: path_to_config = rollback(profile) - elif flake: - path_to_config = nixos_build_flake( - "toplevel", - flake, - no_link=True, - **flake_flags, - ) - set_profile(profile, path_to_config, sudo=args.sudo) else: - path_to_config = nixos_build( - "system", - args.attr, - args.file, - no_out_link=True, - **nix_flags, - ) - set_profile(profile, path_to_config, sudo=args.sudo) + if flake: + path_to_config = nixos_build_flake( + "toplevel", + flake, + no_link=True, + **flake_build_flags, + ) + else: + path_to_config = nixos_build( + "system", + args.attr, + args.file, + no_out_link=True, + **build_flags, + ) + copy_closure(path_to_config, target_host, **copy_flags) + set_profile(profile, path_to_config, target_host, sudo=args.sudo) switch_to_configuration( path_to_config, action, + target_host, sudo=args.sudo, specialisation=args.specialisation, install_bootloader=args.install_bootloader, @@ -214,7 +242,7 @@ def execute(argv: list[str]) -> None: flake, keep_going=True, dry_run=dry_run, - **flake_flags, + **flake_build_flags, ) else: path_to_config = nixos_build( @@ -223,12 +251,13 @@ def execute(argv: list[str]) -> None: args.file, keep_going=True, dry_run=dry_run, - **nix_flags, + **build_flags, ) if action in (Action.TEST, Action.DRY_ACTIVATE): switch_to_configuration( path_to_config, action, + target_host, sudo=args.sudo, specialisation=args.specialisation, ) @@ -240,7 +269,7 @@ def execute(argv: list[str]) -> None: attr, flake, keep_going=True, - **flake_flags, + **flake_build_flags, ) else: path_to_config = nixos_build( @@ -248,12 +277,12 @@ def execute(argv: list[str]) -> None: args.attr, args.file, keep_going=True, - **nix_flags, + **build_flags, ) vm_path = next(path_to_config.glob("bin/run-*-vm"), "./result/bin/run-*-vm") print(f"Done. The virtual machine can be started by running '{vm_path}'") case Action.EDIT: - edit(flake, **flake_flags) + edit(flake, **flake_build_flags) case Action.DRY_RUN: assert False, "DRY_RUN should be a DRY_BUILD alias" case Action.LIST_GENERATIONS: diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py index 6c9f01a115f0..9601aeeb967b 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py @@ -116,7 +116,7 @@ class Profile: @dataclass(frozen=True) -class SSH: +class Ssh: host: str opts: list[str] tty: bool diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py index dbc3b84bd8c4..ae12cc172e3a 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py @@ -12,6 +12,7 @@ from .models import ( GenerationJson, NRError, Profile, + Ssh, ) from .process import run_wrapper from .utils import Args, dict_to_flags, info @@ -19,6 +20,28 @@ from .utils import Args, dict_to_flags, info FLAKE_FLAGS: Final = ["--extra-experimental-features", "nix-command flakes"] +def copy_closure( + closure: Path, + target_host: Ssh | None, + **copy_flags: Args, +) -> None: + host = target_host + if not host: + return + + run_wrapper( + [ + "nix-copy-closure", + *(dict_to_flags(copy_flags)), + "--to", + host.host, + closure, + ], + check=True, + extra_env={"NIX_SSHOPTS": " ".join(host.opts)}, + ) + + def edit(flake: Flake | None, **flake_flags: Args) -> None: "Try to find and open NixOS configuration file in editor." if flake: @@ -277,16 +300,25 @@ def rollback_temporary_profile(profile: Profile) -> Path | None: return None -def set_profile(profile: Profile, path_to_config: Path, sudo: bool) -> None: +def set_profile( + profile: Profile, + path_to_config: Path, + target_host: Ssh | None, + sudo: bool, +) -> None: "Set a path as the current active Nix profile." run_wrapper( - ["nix-env", "-p", profile.path, "--set", path_to_config], check=True, sudo=sudo + ["nix-env", "-p", profile.path, "--set", path_to_config], + check=True, + remote=target_host, + sudo=sudo, ) def switch_to_configuration( path_to_config: Path, action: Action, + target_host: Ssh | None, sudo: bool, install_bootloader: bool = False, specialisation: str | None = None, @@ -310,6 +342,7 @@ def switch_to_configuration( [path_to_config / "bin/switch-to-configuration", str(action)], extra_env={"NIXOS_INSTALL_BOOTLOADER": "1" if install_bootloader else "0"}, check=True, + remote=target_host, sudo=sudo, ) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py index ef08673393a7..dc738bd17285 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py @@ -4,7 +4,7 @@ import os import subprocess from typing import Sequence, TypedDict, Unpack -from .models import SSH +from .models import Ssh # Not exhaustive, but we can always extend it later. @@ -22,7 +22,7 @@ def run_wrapper( check: bool, # make it explicit so we always know if the code is handling errors env: dict[str, str] | None = None, # replaces the current environment extra_env: dict[str, str] | None = None, # appends to the current environment - remote: SSH | None = None, + remote: Ssh | None = None, sudo: bool = False, **kwargs: Unpack[RunKwargs], ) -> subprocess.CompletedProcess[str]: diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py index e5a657c886ae..b7d1dd8e1527 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py @@ -208,6 +208,109 @@ def test_execute_nix_switch_flake(mock_run: Any, tmp_path: Path) -> None: ) +@patch.dict(nr.process.os.environ, {}, clear=True) +@patch(get_qualified_name(nr.process.subprocess.run), autospec=True) +@patch(get_qualified_name(nr.TemporaryDirectory, nr)) # can't autospec +def test_execute_nix_switch_flake_remote( + mock_tmpdir: Any, + mock_run: Any, + tmp_path: Path, +) -> None: + config_path = tmp_path / "test" + config_path.touch() + mock_run.side_effect = [ + # nixos_build_flake + CompletedProcess([], 0, str(config_path)), + # set_profile + CompletedProcess([], 0), + # copy_closure + CompletedProcess([], 0), + # switch_to_configuration + CompletedProcess([], 0), + ] + mock_tmpdir.return_value.name = "/tmp/test" + + nr.execute( + [ + "nixos-rebuild", + "switch", + "--flake", + "/path/to/config#hostname", + "--use-remote-sudo", + "--target-host", + "user@localhost", + ] + ) + + assert mock_run.call_count == 4 + mock_run.assert_has_calls( + [ + call( + [ + "nix", + "--extra-experimental-features", + "nix-command flakes", + "build", + "--print-out-paths", + "/path/to/config#nixosConfigurations.hostname.config.system.build.toplevel", + "--no-link", + ], + check=True, + stdout=PIPE, + **DEFAULT_RUN_KWARGS, + ), + call( + ["nix-copy-closure", "--to", "user@localhost", config_path], + check=True, + **DEFAULT_RUN_KWARGS, + ), + call( + [ + "ssh", + "-t", + "-o", + "ControlMaster=auto", + "-o", + "ControlPath=/tmp/test/ssh-%n", + "-o", + "ControlPersist=60", + "user@localhost", + "--", + "sudo", + "nix-env", + "-p", + Path("/nix/var/nix/profiles/system"), + "--set", + config_path, + ], + check=True, + **DEFAULT_RUN_KWARGS, + ), + call( + [ + "ssh", + "-t", + "-o", + "ControlMaster=auto", + "-o", + "ControlPath=/tmp/test/ssh-%n", + "-o", + "ControlPersist=60", + "user@localhost", + "--", + "sudo", + "env", + "NIXOS_INSTALL_BOOTLOADER=0", + config_path / "bin/switch-to-configuration", + "switch", + ], + check=True, + **DEFAULT_RUN_KWARGS, + ), + ] + ) + + @patch(get_qualified_name(nr.process.subprocess.run), autospec=True) def test_execute_switch_rollback(mock_run: Any, tmp_path: Path) -> None: nixpkgs_path = tmp_path / "nixpkgs" diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py index d2c0442b4369..7f54cff14f0e 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py @@ -101,7 +101,8 @@ def test_profile_from_name(mock_mkdir: Any) -> None: def test_ssh_from_name(monkeypatch: Any, tmpdir: Path) -> None: - assert m.SSH.from_arg("user@localhost", None, tmpdir) == m.SSH( + monkeypatch.setenv("NIX_SSHOPTS", "") + assert m.Ssh.from_arg("user@localhost", None, tmpdir) == m.Ssh( "user@localhost", [ "-o", @@ -114,8 +115,8 @@ def test_ssh_from_name(monkeypatch: Any, tmpdir: Path) -> None: False, ) - monkeypatch.setenv("NIX_SSHOPTS", "-f foo -b bar", tmpdir) - assert m.SSH.from_arg("user@localhost", True, tmpdir) == m.SSH( + monkeypatch.setenv("NIX_SSHOPTS", "-f foo -b bar") + assert m.Ssh.from_arg("user@localhost", True, tmpdir) == m.Ssh( "user@localhost", [ "-f", diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py index 46b89bc355ba..975294889e4f 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py @@ -12,6 +12,21 @@ import nixos_rebuild.nix as n from .helpers import get_qualified_name +@patch(get_qualified_name(n.run_wrapper, n), autospec=True) +def test_copy_closure(mock_run: Any) -> None: + closure = Path("/path/to/closure") + n.copy_closure(closure, None) + mock_run.assert_not_called() + + target_host = m.Ssh("user@host", ["--ssh", "opt"], False) + n.copy_closure(closure, target_host) + mock_run.assert_called_with( + ["nix-copy-closure", "--to", "user@host", closure], + check=True, + extra_env={"NIX_SSHOPTS": "--ssh opt"}, + ) + + @patch(get_qualified_name(n.run_wrapper, n), autospec=True) def test_edit(mock_run: Any, monkeypatch: Any, tmpdir: Any) -> None: # Flake @@ -290,11 +305,17 @@ def test_rollback_temporary_profile(tmp_path: Path) -> None: def test_set_profile(mock_run: Any) -> None: profile_path = Path("/path/to/profile") config_path = Path("/path/to/config") - n.set_profile(m.Profile("system", profile_path), config_path, sudo=False) + n.set_profile( + m.Profile("system", profile_path), + config_path, + target_host=None, + sudo=False, + ) mock_run.assert_called_with( ["nix-env", "-p", profile_path, "--set", config_path], check=True, + remote=None, sudo=False, ) @@ -311,6 +332,7 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: profile_path, m.Action.SWITCH, sudo=False, + target_host=None, specialisation=None, install_bootloader=False, ) @@ -319,6 +341,7 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: extra_env={"NIXOS_INSTALL_BOOTLOADER": "0"}, check=True, sudo=False, + remote=None, ) with pytest.raises(m.NRError) as e: @@ -326,6 +349,7 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: config_path, m.Action.BOOT, sudo=False, + target_host=None, specialisation="special", ) assert ( @@ -342,6 +366,7 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: Path("/path/to/config"), m.Action.TEST, sudo=True, + target_host=m.Ssh("user@localhost", [], False), install_bootloader=True, specialisation="special", ) @@ -353,6 +378,7 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: extra_env={"NIXOS_INSTALL_BOOTLOADER": "1"}, check=True, sudo=True, + remote=m.Ssh("user@localhost", [], False), ) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py index 19a56581b6fd..ae1de83e1780 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py @@ -41,7 +41,7 @@ def test_run(mock_run: Any) -> None: p.run_wrapper( ["test", "--with", "flags"], check=True, - remote=m.SSH("user@localhost", ["--ssh", "opt"], False), + remote=m.Ssh("user@localhost", ["--ssh", "opt"], False), ) mock_run.assert_called_with( ["ssh", "--ssh", "opt", "user@localhost", "--", "test", "--with", "flags"], @@ -69,7 +69,7 @@ def test_run(mock_run: Any) -> None: check=True, sudo=True, extra_env={"FOO": "bar"}, - remote=m.SSH("user@localhost", ["--ssh", "opt"], True), + remote=m.Ssh("user@localhost", ["--ssh", "opt"], True), ) mock_run.assert_called_with( [ @@ -97,5 +97,5 @@ def test_run(mock_run: Any) -> None: ["test", "--with", "flags"], check=False, env={"foo": "bar"}, - remote=m.SSH("user@localhost", [], False), + remote=m.Ssh("user@localhost", [], False), ) From 8bd70ef6992bf9d4c0796bceab6589c3efa1ff10 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Sun, 24 Nov 2024 19:42:54 +0000 Subject: [PATCH 011/166] nixos-rebuild-ng: error when `--rollback` is called with incompatible action --- .../by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py index 7215bc05725f..dbe716f4f35c 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py @@ -230,7 +230,9 @@ def execute(argv: list[str]) -> None: case Action.TEST | Action.BUILD | Action.DRY_BUILD | Action.DRY_ACTIVATE: info("building the system configuration...") dry_run = action == Action.DRY_BUILD - if args.rollback and action in (Action.TEST, Action.BUILD): + if args.rollback: + if action not in (Action.TEST, Action.BUILD): + raise NRError(f"--rollback is incompatible with '{action}'") maybe_path_to_config = rollback_temporary_profile(profile) if maybe_path_to_config: # kinda silly but this makes mypy happy path_to_config = maybe_path_to_config From 56203bca4e15c069d78af349a68b88bb71e978a6 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Sun, 24 Nov 2024 20:30:17 +0000 Subject: [PATCH 012/166] nixos-rebuild-ng: add allow_tty parameter to process.run_wrapper --- .../ni/nixos-rebuild-ng/src/nixos_rebuild/process.py | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py index dc738bd17285..1bdc7d95e36f 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py @@ -22,6 +22,7 @@ def run_wrapper( check: bool, # make it explicit so we always know if the code is handling errors env: dict[str, str] | None = None, # replaces the current environment extra_env: dict[str, str] | None = None, # appends to the current environment + allow_tty: bool = True, remote: Ssh | None = None, sudo: bool = False, **kwargs: Unpack[RunKwargs], @@ -34,7 +35,15 @@ def run_wrapper( args = ["env", *extra_env_args, *args] if sudo: args = ["sudo", *args] - if remote.tty: + if allow_tty: + # SSH's TTY will redirect all output to stdout, that may cause + # unwanted effects when used + assert not kwargs.get( + "capture_output" + ), "SSH's TTY is incompatible with capture_output" + assert not kwargs.get("stderr"), "SSH's TTY is incompatible with stderr" + assert not kwargs.get("stdout"), "SSH's TTY is incompatible with stdout" + if allow_tty and remote.tty: args = ["ssh", "-t", *remote.opts, remote.host, "--", *args] else: args = ["ssh", *remote.opts, remote.host, "--", *args] From 37d6a2688f0d04126a800f28de9f6ac772b4d3a5 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Sun, 24 Nov 2024 20:42:03 +0000 Subject: [PATCH 013/166] nixos-rebuild-ng: get remote hostname --- .../src/nixos_rebuild/__init__.py | 2 +- .../src/nixos_rebuild/models.py | 39 +++++++++++++++---- .../nixos-rebuild-ng/src/tests/test_models.py | 33 +++++++++++----- 3 files changed, 55 insertions(+), 19 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py index dbe716f4f35c..beec4ee33303 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py @@ -177,8 +177,8 @@ def execute(argv: list[str]) -> None: tmpdir_path = Path(tmpdir.name) profile = Profile.from_name(args.profile_name) - flake = Flake.from_arg(args.flake) target_host = Ssh.from_arg(args.target_host, not args.no_ssh_tty, tmpdir_path) + flake = Flake.from_arg(args.flake, target_host) if args.upgrade or args.upgrade_all: upgrade_channels(bool(args.upgrade_all)) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py index 9601aeeb967b..88e2c3fad7af 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py @@ -1,10 +1,13 @@ +from __future__ import annotations + import os import platform import re +import subprocess from dataclasses import dataclass from enum import Enum from pathlib import Path -from typing import Any, ClassVar, Self, TypedDict, override +from typing import Any, Callable, ClassVar, Self, TypedDict, override class NRError(Exception): @@ -52,21 +55,41 @@ class Flake: return f"{self.path}#{self.attr}" @classmethod - def parse(cls, flake_str: str, hostname: str | None = None) -> Self: + def parse( + cls, + flake_str: str, + hostname_fn: Callable[[], str | None] = lambda: None, + ) -> Self: m = cls._re.match(flake_str) assert m is not None, f"got no matches for {flake_str}" attr = m.group("attr") - nixos_attr = f"nixosConfigurations.{attr or hostname or "default"}" + nixos_attr = f"nixosConfigurations.{attr or hostname_fn() or "default"}" return cls(Path(m.group("path")), nixos_attr) @classmethod - def from_arg(cls, flake_arg: Any) -> Self | None: - hostname = platform.node() + def from_arg(cls, flake_arg: Any, target_host: Ssh | None) -> Self | None: + def get_hostname() -> str | None: + if target_host: + from .process import run_wrapper # circumvent circular import + + try: + return run_wrapper( + ["uname", "-n"], + check=True, + capture_output=True, + allow_tty=False, + remote=target_host, + ).stdout.strip() + except (AttributeError, subprocess.CalledProcessError): + return None + else: + return platform.node() + match flake_arg: case str(s): - return cls.parse(s, hostname) + return cls.parse(s, get_hostname) case True: - return cls.parse(".", hostname) + return cls.parse(".", get_hostname) case False: return None case _: @@ -76,7 +99,7 @@ class Flake: # It can be a symlink to the actual flake. if default_path.is_symlink(): default_path = default_path.readlink() - return cls.parse(str(default_path.parent), hostname) + return cls.parse(str(default_path.parent), get_hostname) else: return None diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py index 7f54cff14f0e..b11404baa000 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py @@ -1,4 +1,5 @@ import platform +import subprocess from pathlib import Path from typing import Any from unittest.mock import patch @@ -12,16 +13,15 @@ def test_flake_parse() -> None: assert m.Flake.parse("/path/to/flake#attr") == m.Flake( Path("/path/to/flake"), "nixosConfigurations.attr" ) - assert m.Flake.parse("/path/ to /flake", "hostname") == m.Flake( + assert m.Flake.parse("/path/ to /flake", lambda: "hostname") == m.Flake( Path("/path/ to /flake"), "nixosConfigurations.hostname" ) - assert m.Flake.parse("/path/to/flake", "hostname") == m.Flake( + assert m.Flake.parse("/path/to/flake", lambda: "hostname") == m.Flake( Path("/path/to/flake"), "nixosConfigurations.hostname" ) assert m.Flake.parse(".#attr") == m.Flake(Path("."), "nixosConfigurations.attr") assert m.Flake.parse("#attr") == m.Flake(Path("."), "nixosConfigurations.attr") - assert m.Flake.parse(".", None) == m.Flake(Path("."), "nixosConfigurations.default") - assert m.Flake.parse("", "") == m.Flake(Path("."), "nixosConfigurations.default") + assert m.Flake.parse(".") == m.Flake(Path("."), "nixosConfigurations.default") @patch(get_qualified_name(platform.node), autospec=True) @@ -29,15 +29,17 @@ def test_flake_from_arg(mock_node: Any) -> None: mock_node.return_value = "hostname" # Flake string - assert m.Flake.from_arg("/path/to/flake#attr") == m.Flake( + assert m.Flake.from_arg("/path/to/flake#attr", None) == m.Flake( Path("/path/to/flake"), "nixosConfigurations.attr" ) # False - assert m.Flake.from_arg(False) is None + assert m.Flake.from_arg(False, None) is None # True - assert m.Flake.from_arg(True) == m.Flake(Path("."), "nixosConfigurations.hostname") + assert m.Flake.from_arg(True, None) == m.Flake( + Path("."), "nixosConfigurations.hostname" + ) # None when we do not have /etc/nixos/flake.nix with patch( @@ -45,7 +47,7 @@ def test_flake_from_arg(mock_node: Any) -> None: autospec=True, return_value=False, ): - assert m.Flake.from_arg(None) is None + assert m.Flake.from_arg(None, None) is None # None when we have a file in /etc/nixos/flake.nix with ( @@ -60,7 +62,7 @@ def test_flake_from_arg(mock_node: Any) -> None: return_value=False, ), ): - assert m.Flake.from_arg(None) == m.Flake( + assert m.Flake.from_arg(None, None) == m.Flake( Path("/etc/nixos"), "nixosConfigurations.hostname" ) @@ -81,10 +83,21 @@ def test_flake_from_arg(mock_node: Any) -> None: return_value=Path("/path/to/flake.nix"), ), ): - assert m.Flake.from_arg(None) == m.Flake( + assert m.Flake.from_arg(None, None) == m.Flake( Path("/path/to"), "nixosConfigurations.hostname" ) + with ( + patch( + get_qualified_name(m.subprocess.run), + autospec=True, + return_value=subprocess.CompletedProcess([], 0, "remote-hostname\n"), + ), + ): + assert m.Flake.from_arg("/path/to", m.Ssh("user@host", [], False)) == m.Flake( + Path("/path/to"), "nixosConfigurations.remote-hostname" + ) + @patch(get_qualified_name(m.Path.mkdir, m), autospec=True) def test_profile_from_name(mock_mkdir: Any) -> None: From 866e1786e331258f75ace1b191509d6bb3a41646 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Sun, 24 Nov 2024 20:51:21 +0000 Subject: [PATCH 014/166] nixos-rebuild-ng: move models.Ssh to process.Remote --- .../src/nixos_rebuild/__init__.py | 5 ++-- .../src/nixos_rebuild/models.py | 29 ++---------------- .../nixos-rebuild-ng/src/nixos_rebuild/nix.py | 8 ++--- .../src/nixos_rebuild/process.py | 30 ++++++++++++++++--- .../nixos-rebuild-ng/src/tests/test_models.py | 12 ++++---- .../ni/nixos-rebuild-ng/src/tests/test_nix.py | 6 ++-- .../src/tests/test_process.py | 6 ++-- 7 files changed, 48 insertions(+), 48 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py index beec4ee33303..f318f5bc918a 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py @@ -7,7 +7,7 @@ from subprocess import run from tempfile import TemporaryDirectory from typing import assert_never -from .models import Action, Flake, NRError, Profile, Ssh +from .models import Action, Flake, NRError, Profile from .nix import ( copy_closure, edit, @@ -22,6 +22,7 @@ from .nix import ( switch_to_configuration, upgrade_channels, ) +from .process import Remote from .utils import flags_to_dict, info VERBOSE = 0 @@ -177,7 +178,7 @@ def execute(argv: list[str]) -> None: tmpdir_path = Path(tmpdir.name) profile = Profile.from_name(args.profile_name) - target_host = Ssh.from_arg(args.target_host, not args.no_ssh_tty, tmpdir_path) + target_host = Remote.from_arg(args.target_host, not args.no_ssh_tty, tmpdir_path) flake = Flake.from_arg(args.flake, target_host) if args.upgrade or args.upgrade_all: diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py index 88e2c3fad7af..21c06ef6b117 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py @@ -1,6 +1,5 @@ from __future__ import annotations -import os import platform import re import subprocess @@ -9,6 +8,8 @@ from enum import Enum from pathlib import Path from typing import Any, Callable, ClassVar, Self, TypedDict, override +from .process import Remote, run_wrapper + class NRError(Exception): "nixos-rebuild general error." @@ -67,11 +68,9 @@ class Flake: return cls(Path(m.group("path")), nixos_attr) @classmethod - def from_arg(cls, flake_arg: Any, target_host: Ssh | None) -> Self | None: + def from_arg(cls, flake_arg: Any, target_host: Remote | None) -> Self | None: def get_hostname() -> str | None: if target_host: - from .process import run_wrapper # circumvent circular import - try: return run_wrapper( ["uname", "-n"], @@ -136,25 +135,3 @@ class Profile: path = Path("/nix/var/nix/profiles/system-profiles") / name path.parent.mkdir(mode=0o755, parents=True, exist_ok=True) return cls(name, path) - - -@dataclass(frozen=True) -class Ssh: - host: str - opts: list[str] - tty: bool - - @classmethod - def from_arg(cls, host: str | None, tty: bool | None, tmp_dir: Path) -> Self | None: - if host: - opts = os.getenv("NIX_SSHOPTS", "").split() + [ - "-o", - "ControlMaster=auto", - "-o", - f"ControlPath={tmp_dir / "ssh-%n"}", - "-o", - "ControlPersist=60", - ] - return cls(host, opts, bool(tty)) - else: - return None diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py index ae12cc172e3a..edc1628145da 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py @@ -12,7 +12,7 @@ from .models import ( GenerationJson, NRError, Profile, - Ssh, + Remote, ) from .process import run_wrapper from .utils import Args, dict_to_flags, info @@ -22,7 +22,7 @@ FLAKE_FLAGS: Final = ["--extra-experimental-features", "nix-command flakes"] def copy_closure( closure: Path, - target_host: Ssh | None, + target_host: Remote | None, **copy_flags: Args, ) -> None: host = target_host @@ -303,7 +303,7 @@ def rollback_temporary_profile(profile: Profile) -> Path | None: def set_profile( profile: Profile, path_to_config: Path, - target_host: Ssh | None, + target_host: Remote | None, sudo: bool, ) -> None: "Set a path as the current active Nix profile." @@ -318,7 +318,7 @@ def set_profile( def switch_to_configuration( path_to_config: Path, action: Action, - target_host: Ssh | None, + target_host: Remote | None, sudo: bool, install_bootloader: bool = False, specialisation: str | None = None, diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py index 1bdc7d95e36f..22436cc621f5 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py @@ -2,9 +2,9 @@ from __future__ import annotations import os import subprocess -from typing import Sequence, TypedDict, Unpack - -from .models import Ssh +from dataclasses import dataclass +from pathlib import Path +from typing import Self, Sequence, TypedDict, Unpack # Not exhaustive, but we can always extend it later. @@ -16,6 +16,28 @@ class RunKwargs(TypedDict, total=False): stdout: int | None +@dataclass(frozen=True) +class Remote: + host: str + opts: list[str] + tty: bool + + @classmethod + def from_arg(cls, host: str | None, tty: bool | None, tmp_dir: Path) -> Self | None: + if host: + opts = os.getenv("NIX_SSHOPTS", "").split() + [ + "-o", + "ControlMaster=auto", + "-o", + f"ControlPath={tmp_dir / "ssh-%n"}", + "-o", + "ControlPersist=60", + ] + return cls(host, opts, bool(tty)) + else: + return None + + def run_wrapper( args: Sequence[str | bytes | os.PathLike[str] | os.PathLike[bytes]], *, @@ -23,7 +45,7 @@ def run_wrapper( env: dict[str, str] | None = None, # replaces the current environment extra_env: dict[str, str] | None = None, # appends to the current environment allow_tty: bool = True, - remote: Ssh | None = None, + remote: Remote | None = None, sudo: bool = False, **kwargs: Unpack[RunKwargs], ) -> subprocess.CompletedProcess[str]: diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py index b11404baa000..04e56522cd46 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py @@ -94,9 +94,9 @@ def test_flake_from_arg(mock_node: Any) -> None: return_value=subprocess.CompletedProcess([], 0, "remote-hostname\n"), ), ): - assert m.Flake.from_arg("/path/to", m.Ssh("user@host", [], False)) == m.Flake( - Path("/path/to"), "nixosConfigurations.remote-hostname" - ) + assert m.Flake.from_arg( + "/path/to", m.Remote("user@host", [], False) + ) == m.Flake(Path("/path/to"), "nixosConfigurations.remote-hostname") @patch(get_qualified_name(m.Path.mkdir, m), autospec=True) @@ -113,9 +113,9 @@ def test_profile_from_name(mock_mkdir: Any) -> None: mock_mkdir.assert_called_once() -def test_ssh_from_name(monkeypatch: Any, tmpdir: Path) -> None: +def test_remote_from_name(monkeypatch: Any, tmpdir: Path) -> None: monkeypatch.setenv("NIX_SSHOPTS", "") - assert m.Ssh.from_arg("user@localhost", None, tmpdir) == m.Ssh( + assert m.Remote.from_arg("user@localhost", None, tmpdir) == m.Remote( "user@localhost", [ "-o", @@ -129,7 +129,7 @@ def test_ssh_from_name(monkeypatch: Any, tmpdir: Path) -> None: ) monkeypatch.setenv("NIX_SSHOPTS", "-f foo -b bar") - assert m.Ssh.from_arg("user@localhost", True, tmpdir) == m.Ssh( + assert m.Remote.from_arg("user@localhost", True, tmpdir) == m.Remote( "user@localhost", [ "-f", diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py index 975294889e4f..23c2567057da 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py @@ -18,7 +18,7 @@ def test_copy_closure(mock_run: Any) -> None: n.copy_closure(closure, None) mock_run.assert_not_called() - target_host = m.Ssh("user@host", ["--ssh", "opt"], False) + target_host = m.Remote("user@host", ["--ssh", "opt"], False) n.copy_closure(closure, target_host) mock_run.assert_called_with( ["nix-copy-closure", "--to", "user@host", closure], @@ -366,7 +366,7 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: Path("/path/to/config"), m.Action.TEST, sudo=True, - target_host=m.Ssh("user@localhost", [], False), + target_host=m.Remote("user@localhost", [], False), install_bootloader=True, specialisation="special", ) @@ -378,7 +378,7 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: extra_env={"NIXOS_INSTALL_BOOTLOADER": "1"}, check=True, sudo=True, - remote=m.Ssh("user@localhost", [], False), + remote=m.Remote("user@localhost", [], False), ) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py index ae1de83e1780..fc9b5d8e634c 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py @@ -41,7 +41,7 @@ def test_run(mock_run: Any) -> None: p.run_wrapper( ["test", "--with", "flags"], check=True, - remote=m.Ssh("user@localhost", ["--ssh", "opt"], False), + remote=m.Remote("user@localhost", ["--ssh", "opt"], False), ) mock_run.assert_called_with( ["ssh", "--ssh", "opt", "user@localhost", "--", "test", "--with", "flags"], @@ -69,7 +69,7 @@ def test_run(mock_run: Any) -> None: check=True, sudo=True, extra_env={"FOO": "bar"}, - remote=m.Ssh("user@localhost", ["--ssh", "opt"], True), + remote=m.Remote("user@localhost", ["--ssh", "opt"], True), ) mock_run.assert_called_with( [ @@ -97,5 +97,5 @@ def test_run(mock_run: Any) -> None: ["test", "--with", "flags"], check=False, env={"foo": "bar"}, - remote=m.Ssh("user@localhost", [], False), + remote=m.Remote("user@localhost", [], False), ) From f443299c5825738a01d064635037684bb5a83fdd Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Mon, 25 Nov 2024 18:49:03 +0000 Subject: [PATCH 015/166] nixos-rebuild-ng: remove support for env in process.run_wrapper --- .../src/nixos_rebuild/process.py | 23 +++++++++---------- .../src/tests/test_process.py | 16 ++----------- 2 files changed, 13 insertions(+), 26 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py index 22436cc621f5..68383a81fef7 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py @@ -42,36 +42,35 @@ def run_wrapper( args: Sequence[str | bytes | os.PathLike[str] | os.PathLike[bytes]], *, check: bool, # make it explicit so we always know if the code is handling errors - env: dict[str, str] | None = None, # replaces the current environment - extra_env: dict[str, str] | None = None, # appends to the current environment + extra_env: dict[str, str] | None = None, allow_tty: bool = True, remote: Remote | None = None, sudo: bool = False, **kwargs: Unpack[RunKwargs], ) -> subprocess.CompletedProcess[str]: "Wrapper around `subprocess.run` that supports extra functionality." + if remote and allow_tty: + # SSH's TTY will redirect all output to stdout, that may cause + # unwanted effects when used + assert not kwargs.get( + "capture_output" + ), "SSH's TTY is incompatible with capture_output" + assert not kwargs.get("stderr"), "SSH's TTY is incompatible with stderr" + assert not kwargs.get("stdout"), "SSH's TTY is incompatible with stdout" + env = None if remote: - assert env is None, "'env' can't be used with 'remote'" if extra_env: extra_env_args = [f"{env}={value}" for env, value in extra_env.items()] args = ["env", *extra_env_args, *args] if sudo: args = ["sudo", *args] - if allow_tty: - # SSH's TTY will redirect all output to stdout, that may cause - # unwanted effects when used - assert not kwargs.get( - "capture_output" - ), "SSH's TTY is incompatible with capture_output" - assert not kwargs.get("stderr"), "SSH's TTY is incompatible with stderr" - assert not kwargs.get("stdout"), "SSH's TTY is incompatible with stdout" if allow_tty and remote.tty: args = ["ssh", "-t", *remote.opts, remote.host, "--", *args] else: args = ["ssh", *remote.opts, remote.host, "--", *args] else: if extra_env: - env = (env or os.environ) | extra_env + env = os.environ | extra_env if sudo: args = ["sudo", *args] diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py index fc9b5d8e634c..ebbc0a288606 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py @@ -51,19 +51,6 @@ def test_run(mock_run: Any) -> None: env=None, ) - p.run_wrapper( - ["test", "--with", "flags"], - check=False, - env={"FOO": "bar"}, - ) - mock_run.assert_called_with( - ["test", "--with", "flags"], - check=False, - env={"FOO": "bar"}, - text=True, - errors="surrogateescape", - ) - p.run_wrapper( ["test", "--with", "flags"], check=True, @@ -96,6 +83,7 @@ def test_run(mock_run: Any) -> None: p.run_wrapper( ["test", "--with", "flags"], check=False, - env={"foo": "bar"}, + allow_tty=True, remote=m.Remote("user@localhost", [], False), + capture_output=True, ) From e37e7e348dc192f73b375b31d7dbdb033ec7905e Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Mon, 25 Nov 2024 19:19:20 +0000 Subject: [PATCH 016/166] nixos-rebuild-ng: cleanup SSH ControlMaster at exit --- .../ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py | 4 +++- .../ni/nixos-rebuild-ng/src/nixos_rebuild/process.py | 7 +++++++ 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py index f318f5bc918a..081c179ad970 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py @@ -1,4 +1,5 @@ import argparse +import atexit import json import os import sys @@ -22,7 +23,7 @@ from .nix import ( switch_to_configuration, upgrade_channels, ) -from .process import Remote +from .process import Remote, cleanup_ssh from .utils import flags_to_dict, info VERBOSE = 0 @@ -176,6 +177,7 @@ def execute(argv: list[str]) -> None: # Will be cleaned up on exit automatically. tmpdir = TemporaryDirectory(prefix="nixos-rebuild.") tmpdir_path = Path(tmpdir.name) + atexit.register(cleanup_ssh, tmpdir_path) profile = Profile.from_name(args.profile_name) target_host = Remote.from_arg(args.target_host, not args.no_ssh_tty, tmpdir_path) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py index 68383a81fef7..cfa1b07ea823 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py @@ -26,6 +26,7 @@ class Remote: def from_arg(cls, host: str | None, tty: bool | None, tmp_dir: Path) -> Self | None: if host: opts = os.getenv("NIX_SSHOPTS", "").split() + [ + # SSH ControlMaster flags, allow for faster re-connection "-o", "ControlMaster=auto", "-o", @@ -38,6 +39,12 @@ class Remote: return None +def cleanup_ssh(tmp_dir: Path) -> None: + "Close SSH ControlMaster connection." + for ctrl in tmp_dir.glob("ssh-*"): + subprocess.run(["ssh", "-o", f"ControlPath={ctrl}", "exit"], check=False) + + def run_wrapper( args: Sequence[str | bytes | os.PathLike[str] | os.PathLike[bytes]], *, From 4adad7f6648ae7e373c6bf4ffeac032c7088a9d4 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Mon, 25 Nov 2024 20:04:35 +0000 Subject: [PATCH 017/166] nixos-rebuild-ng: implement `--target-host` for `--rollback` --- .../src/nixos_rebuild/__init__.py | 18 +++++- .../nixos-rebuild-ng/src/nixos_rebuild/nix.py | 34 ++++++++-- .../ni/nixos-rebuild-ng/src/tests/test_nix.py | 63 ++++++++++++++++--- 3 files changed, 100 insertions(+), 15 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py index 081c179ad970..aea83f9a1842 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py @@ -118,6 +118,16 @@ def parse_args(argv: list[str]) -> argparse.Namespace: if args.action == Action.EDIT.value and (args.file or args.attr): parser.error("--file and --attr are not supported with 'edit'") + if args.target_host and args.action not in ( + Action.SWITCH.value, + Action.BOOT.value, + Action.TEST.value, + Action.BUILD.value, + Action.DRY_BUILD.value, + Action.DRY_ACTIVATE.value, + ): + parser.error(f"--target-host is not supported with '{args.action}'") + if args.flake and (args.file or args.attr): parser.error("--flake cannot be used with --file or --attr") @@ -203,7 +213,7 @@ def execute(argv: list[str]) -> None: case Action.SWITCH | Action.BOOT: info("building the system configuration...") if args.rollback: - path_to_config = rollback(profile) + path_to_config = rollback(profile, target_host, sudo=args.sudo) else: if flake: path_to_config = nixos_build_flake( @@ -236,7 +246,11 @@ def execute(argv: list[str]) -> None: if args.rollback: if action not in (Action.TEST, Action.BUILD): raise NRError(f"--rollback is incompatible with '{action}'") - maybe_path_to_config = rollback_temporary_profile(profile) + maybe_path_to_config = rollback_temporary_profile( + profile, + target_host, + sudo=args.sudo, + ) if maybe_path_to_config: # kinda silly but this makes mypy happy path_to_config = maybe_path_to_config else: diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py index edc1628145da..51799f89a1fc 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py @@ -149,7 +149,12 @@ def _parse_generation_from_nix_env(line: str) -> Generation: ) -def get_generations(profile: Profile, lock_profile: bool = False) -> list[Generation]: +def get_generations( + profile: Profile, + target_host: Remote | None = None, + using_nix_env: bool = False, + sudo: bool = False, +) -> list[Generation]: """Get all NixOS generations from profile. Includes generation ID (e.g.: 1, 2), timestamp (e.g.: when it was created) @@ -161,7 +166,7 @@ def get_generations(profile: Profile, lock_profile: bool = False) -> list[Genera raise NRError(f"no profile '{profile.name}' found") result = [] - if lock_profile: + if using_nix_env: # Using `nix-env --list-generations` needs root to lock the profile # TODO: do we actually need to lock profile for e.g.: rollback? # https://github.com/NixOS/nix/issues/5144 @@ -169,10 +174,13 @@ def get_generations(profile: Profile, lock_profile: bool = False) -> list[Genera ["nix-env", "-p", profile.path, "--list-generations"], stdout=PIPE, check=True, + remote=target_host, + sudo=sudo, ) for line in r.stdout.splitlines(): result.append(_parse_generation_from_nix_env(line)) else: + assert not target_host, "target_host is not supported when using_nix_env=False" for p in profile.path.parent.glob("system-*-link"): result.append(_parse_generation_from_nix_store(p, profile)) return sorted(result, key=lambda d: d.id) @@ -279,16 +287,30 @@ def nixos_build_flake( return Path(r.stdout.strip()) -def rollback(profile: Profile) -> Path: +def rollback(profile: Profile, target_host: Remote | None, sudo: bool) -> Path: "Rollback Nix profile, like one created by `nixos-rebuild switch`." - run_wrapper(["nix-env", "--rollback", "-p", profile.path], check=True) + run_wrapper( + ["nix-env", "--rollback", "-p", profile.path], + check=True, + remote=target_host, + sudo=sudo, + ) # Rollback config PATH is the own profile return profile.path -def rollback_temporary_profile(profile: Profile) -> Path | None: +def rollback_temporary_profile( + profile: Profile, + target_host: Remote | None, + sudo: bool, +) -> Path | None: "Rollback a temporary Nix profile, like one created by `nixos-rebuild test`." - generations = get_generations(profile, lock_profile=True) + generations = get_generations( + profile, + target_host=target_host, + using_nix_env=True, + sudo=sudo, + ) previous_gen_id = None for generation in generations: if not generation.current: diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py index 23c2567057da..61686a038f03 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py @@ -122,7 +122,7 @@ def test_get_generations_from_nix_store(tmp_path: Path) -> None: assert n.get_generations( m.Profile("system", tmp_path / "system"), - lock_profile=False, + using_nix_env=False, ) == [ m.Generation(id=1, current=False, timestamp=ANY), m.Generation(id=2, current=True, timestamp=ANY), @@ -147,7 +147,7 @@ def test_get_generations_from_nix_env(mock_run: Any, tmp_path: Path) -> None: path = tmp_path / "test" path.touch() - assert n.get_generations(m.Profile("system", path), lock_profile=True) == [ + assert n.get_generations(m.Profile("system", path), using_nix_env=True) == [ m.Generation(id=2082, current=False, timestamp="2024-11-07 22:58:56"), m.Generation(id=2083, current=False, timestamp="2024-11-07 22:59:41"), m.Generation(id=2084, current=True, timestamp="2024-11-07 23:54:17"), @@ -268,8 +268,28 @@ def test_rollback(mock_run: Any, tmp_path: Path) -> None: profile = m.Profile("system", path) - assert n.rollback(profile) == profile.path - mock_run.assert_called_with(["nix-env", "--rollback", "-p", path], check=True) + assert n.rollback(profile, None, False) == profile.path + mock_run.assert_called_with( + ["nix-env", "--rollback", "-p", path], + check=True, + remote=None, + sudo=False, + ) + + assert ( + n.rollback( + profile, + m.Remote("user@localhost", [], False), + True, + ) + == profile.path + ) + mock_run.assert_called_with( + ["nix-env", "--rollback", "-p", path], + check=True, + remote=m.Remote("user@localhost", [], False), + sudo=True, + ) def test_rollback_temporary_profile(tmp_path: Path) -> None: @@ -288,17 +308,46 @@ def test_rollback_temporary_profile(tmp_path: Path) -> None: """), ) assert ( - n.rollback_temporary_profile(m.Profile("system", path)) + n.rollback_temporary_profile(m.Profile("system", path), None, False) == path.parent / "system-2083-link" ) + mock_run.assert_called_with( + [ + "nix-env", + "-p", + path, + "--list-generations", + ], + stdout=PIPE, + check=True, + remote=None, + sudo=False, + ) + assert ( - n.rollback_temporary_profile(m.Profile("foo", path)) + n.rollback_temporary_profile( + m.Profile("foo", path), + m.Remote("user@localhost", [], False), + True, + ) == path.parent / "foo-2083-link" ) + mock_run.assert_called_with( + [ + "nix-env", + "-p", + path, + "--list-generations", + ], + stdout=PIPE, + check=True, + remote=m.Remote("user@localhost", [], False), + sudo=True, + ) with patch(get_qualified_name(n.run_wrapper, n), autospec=True) as mock_run: mock_run.return_value = CompletedProcess([], 0, stdout="") - assert n.rollback_temporary_profile(profile) is None + assert n.rollback_temporary_profile(profile, None, False) is None @patch(get_qualified_name(n.run_wrapper, n), autospec=True) From 10f2b080c31dba1b5c27055dc6e50369fc83aaeb Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Tue, 26 Nov 2024 09:37:47 +0000 Subject: [PATCH 018/166] nixos-rebuild-ng: move test to the correct file --- .../src/nixos_rebuild/utils.py | 2 +- .../nixos-rebuild-ng/src/tests/test_models.py | 34 ------------------ .../src/tests/test_process.py | 35 +++++++++++++++++++ 3 files changed, 36 insertions(+), 35 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/utils.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/utils.py index 6c96358441e1..3c2f9e47bc48 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/utils.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/utils.py @@ -13,7 +13,7 @@ def dict_to_flags(d: dict[str, Args]) -> list[str]: flag = f"--{'-'.join(key.split('_'))}" match value: case None | False | 0 | []: - pass + continue case True: flags.append(flag) case int(): diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py index 04e56522cd46..41fb770970ca 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py @@ -111,37 +111,3 @@ def test_profile_from_name(mock_mkdir: Any) -> None: Path("/nix/var/nix/profiles/system-profiles/something"), ) mock_mkdir.assert_called_once() - - -def test_remote_from_name(monkeypatch: Any, tmpdir: Path) -> None: - monkeypatch.setenv("NIX_SSHOPTS", "") - assert m.Remote.from_arg("user@localhost", None, tmpdir) == m.Remote( - "user@localhost", - [ - "-o", - "ControlMaster=auto", - "-o", - f"ControlPath={tmpdir / "ssh-%n"}", - "-o", - "ControlPersist=60", - ], - False, - ) - - monkeypatch.setenv("NIX_SSHOPTS", "-f foo -b bar") - assert m.Remote.from_arg("user@localhost", True, tmpdir) == m.Remote( - "user@localhost", - [ - "-f", - "foo", - "-b", - "bar", - "-o", - "ControlMaster=auto", - "-o", - f"ControlPath={tmpdir / "ssh-%n"}", - "-o", - "ControlPersist=60", - ], - True, - ) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py index ebbc0a288606..5d13954b7b7e 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py @@ -1,3 +1,4 @@ +from pathlib import Path from typing import Any from unittest.mock import patch @@ -87,3 +88,37 @@ def test_run(mock_run: Any) -> None: remote=m.Remote("user@localhost", [], False), capture_output=True, ) + + +def test_remote_from_name(monkeypatch: Any, tmpdir: Path) -> None: + monkeypatch.setenv("NIX_SSHOPTS", "") + assert m.Remote.from_arg("user@localhost", None, tmpdir) == m.Remote( + "user@localhost", + opts=[ + "-o", + "ControlMaster=auto", + "-o", + f"ControlPath={tmpdir / "ssh-%n"}", + "-o", + "ControlPersist=60", + ], + tty=False, + ) + + monkeypatch.setenv("NIX_SSHOPTS", "-f foo -b bar") + assert m.Remote.from_arg("user@localhost", True, tmpdir) == m.Remote( + "user@localhost", + opts=[ + "-f", + "foo", + "-b", + "bar", + "-o", + "ControlMaster=auto", + "-o", + f"ControlPath={tmpdir / "ssh-%n"}", + "-o", + "ControlPersist=60", + ], + tty=True, + ) From 2e4d7553511336eed829c3d417bfc6fbbb8f15f2 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Tue, 26 Nov 2024 11:10:53 +0000 Subject: [PATCH 019/166] nixos-rebuild-ng: do not use TTY for `--target-host` Instead this commit introduces the `--ask-sudo-password` that stores the password in memory and injects it via `stdin` if the user wants. --- .../src/nixos_rebuild/__init__.py | 14 ++++- .../src/nixos_rebuild/models.py | 1 - .../nixos-rebuild-ng/src/nixos_rebuild/nix.py | 6 +- .../src/nixos_rebuild/process.py | 39 ++++++------ .../nixos-rebuild-ng/src/tests/test_main.py | 9 ++- .../nixos-rebuild-ng/src/tests/test_models.py | 6 +- .../ni/nixos-rebuild-ng/src/tests/test_nix.py | 28 +++------ .../src/tests/test_process.py | 61 +++++++++---------- 8 files changed, 83 insertions(+), 81 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py index aea83f9a1842..5ad716c03f6f 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py @@ -50,8 +50,9 @@ def parse_args(argv: list[str]) -> argparse.Namespace: parser.add_argument("--upgrade-all", action="store_true") parser.add_argument("--json", action="store_true") parser.add_argument("--sudo", action="store_true") + parser.add_argument("--ask-sudo-password", action="store_true") parser.add_argument("--use-remote-sudo", action="store_true") # deprecated - parser.add_argument("--no-ssh-tty", action="store_true") + parser.add_argument("--no-ssh-tty", action="store_true") # deprecated # parser.add_argument("--build-host") # TODO parser.add_argument("--target-host") parser.add_argument("--verbose", "-v", action="count", default=0) @@ -101,6 +102,9 @@ def parse_args(argv: list[str]) -> argparse.Namespace: if args.action == Action.DRY_RUN.value: args.action = Action.DRY_BUILD.value + if args.ask_sudo_password: + args.sudo = True + # TODO: use deprecated=True in Python >=3.13 if args.install_grub: info( @@ -115,6 +119,12 @@ def parse_args(argv: list[str]) -> argparse.Namespace: ) args.sudo = True + # TODO: use deprecated=True in Python >=3.13 + if args.no_ssh_tty: + info( + f"{parser.prog}: warning: --no-ssh-tty deprecated, SSH's pseudo-TTY is never used anymore" + ) + if args.action == Action.EDIT.value and (args.file or args.attr): parser.error("--file and --attr are not supported with 'edit'") @@ -190,7 +200,7 @@ def execute(argv: list[str]) -> None: atexit.register(cleanup_ssh, tmpdir_path) profile = Profile.from_name(args.profile_name) - target_host = Remote.from_arg(args.target_host, not args.no_ssh_tty, tmpdir_path) + target_host = Remote.from_arg(args.target_host, args.ask_sudo_password, tmpdir_path) flake = Flake.from_arg(args.flake, target_host) if args.upgrade or args.upgrade_all: diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py index 21c06ef6b117..6fed37cd53ff 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py @@ -76,7 +76,6 @@ class Flake: ["uname", "-n"], check=True, capture_output=True, - allow_tty=False, remote=target_host, ).stdout.strip() except (AttributeError, subprocess.CalledProcessError): diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py index 51799f89a1fc..13e6e4024443 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py @@ -32,7 +32,7 @@ def copy_closure( run_wrapper( [ "nix-copy-closure", - *(dict_to_flags(copy_flags)), + *dict_to_flags(copy_flags), "--to", host.host, closure, @@ -50,7 +50,7 @@ def edit(flake: Flake | None, **flake_flags: Args) -> None: "nix", *FLAKE_FLAGS, "edit", - *(dict_to_flags(flake_flags)), + *dict_to_flags(flake_flags), "--", str(flake), ], @@ -281,8 +281,8 @@ def nixos_build_flake( "build", "--print-out-paths", f"{flake}.config.system.build.{attr}", + *dict_to_flags(flake_flags), ] - run_args += dict_to_flags(flake_flags) r = run_wrapper(run_args, check=True, stdout=PIPE) return Path(r.stdout.strip()) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py index cfa1b07ea823..2b23e88a2dbc 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py @@ -3,6 +3,7 @@ from __future__ import annotations import os import subprocess from dataclasses import dataclass +from getpass import getpass from pathlib import Path from typing import Self, Sequence, TypedDict, Unpack @@ -10,9 +11,7 @@ from typing import Self, Sequence, TypedDict, Unpack # Not exhaustive, but we can always extend it later. class RunKwargs(TypedDict, total=False): capture_output: bool - input: str | None stderr: int | None - stdin: int | None stdout: int | None @@ -20,10 +19,15 @@ class RunKwargs(TypedDict, total=False): class Remote: host: str opts: list[str] - tty: bool + sudo_password: str | None @classmethod - def from_arg(cls, host: str | None, tty: bool | None, tmp_dir: Path) -> Self | None: + def from_arg( + cls, + host: str | None, + ask_sudo_password: bool | None, + tmp_dir: Path, + ) -> Self | None: if host: opts = os.getenv("NIX_SSHOPTS", "").split() + [ # SSH ControlMaster flags, allow for faster re-connection @@ -34,7 +38,10 @@ class Remote: "-o", "ControlPersist=60", ] - return cls(host, opts, bool(tty)) + sudo_password = None + if ask_sudo_password: + sudo_password = getpass(f"[sudo] password for {host}: ") + return cls(host, opts, sudo_password) else: return None @@ -50,31 +57,24 @@ def run_wrapper( *, check: bool, # make it explicit so we always know if the code is handling errors extra_env: dict[str, str] | None = None, - allow_tty: bool = True, remote: Remote | None = None, sudo: bool = False, **kwargs: Unpack[RunKwargs], ) -> subprocess.CompletedProcess[str]: "Wrapper around `subprocess.run` that supports extra functionality." - if remote and allow_tty: - # SSH's TTY will redirect all output to stdout, that may cause - # unwanted effects when used - assert not kwargs.get( - "capture_output" - ), "SSH's TTY is incompatible with capture_output" - assert not kwargs.get("stderr"), "SSH's TTY is incompatible with stderr" - assert not kwargs.get("stdout"), "SSH's TTY is incompatible with stdout" env = None + input = None if remote: if extra_env: extra_env_args = [f"{env}={value}" for env, value in extra_env.items()] args = ["env", *extra_env_args, *args] if sudo: - args = ["sudo", *args] - if allow_tty and remote.tty: - args = ["ssh", "-t", *remote.opts, remote.host, "--", *args] - else: - args = ["ssh", *remote.opts, remote.host, "--", *args] + if remote.sudo_password: + args = ["sudo", "--prompt=", "--stdin", *args] + input = remote.sudo_password + "\n" + else: + args = ["sudo", *args] + args = ["ssh", *remote.opts, remote.host, "--", *args] else: if extra_env: env = os.environ | extra_env @@ -85,6 +85,7 @@ def run_wrapper( args, check=check, env=env, + input=input, # Hope nobody is using NixOS with non-UTF8 encodings, but "surrogateescape" # should still work in those systems. text=True, diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py index b7d1dd8e1527..09ade9008ac2 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py @@ -10,7 +10,12 @@ import nixos_rebuild as nr from .helpers import get_qualified_name -DEFAULT_RUN_KWARGS = {"text": True, "errors": "surrogateescape", "env": ANY} +DEFAULT_RUN_KWARGS = { + "env": ANY, + "input": None, + "text": True, + "errors": "surrogateescape", +} def test_parse_args() -> None: @@ -267,7 +272,6 @@ def test_execute_nix_switch_flake_remote( call( [ "ssh", - "-t", "-o", "ControlMaster=auto", "-o", @@ -289,7 +293,6 @@ def test_execute_nix_switch_flake_remote( call( [ "ssh", - "-t", "-o", "ControlMaster=auto", "-o", diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py index 41fb770970ca..f30ef4059310 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py @@ -94,9 +94,9 @@ def test_flake_from_arg(mock_node: Any) -> None: return_value=subprocess.CompletedProcess([], 0, "remote-hostname\n"), ), ): - assert m.Flake.from_arg( - "/path/to", m.Remote("user@host", [], False) - ) == m.Flake(Path("/path/to"), "nixosConfigurations.remote-hostname") + assert m.Flake.from_arg("/path/to", m.Remote("user@host", [], None)) == m.Flake( + Path("/path/to"), "nixosConfigurations.remote-hostname" + ) @patch(get_qualified_name(m.Path.mkdir, m), autospec=True) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py index 61686a038f03..fd58a050eec8 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py @@ -18,7 +18,7 @@ def test_copy_closure(mock_run: Any) -> None: n.copy_closure(closure, None) mock_run.assert_not_called() - target_host = m.Remote("user@host", ["--ssh", "opt"], False) + target_host = m.Remote("user@host", ["--ssh", "opt"], None) n.copy_closure(closure, target_host) mock_run.assert_called_with( ["nix-copy-closure", "--to", "user@host", closure], @@ -276,18 +276,12 @@ def test_rollback(mock_run: Any, tmp_path: Path) -> None: sudo=False, ) - assert ( - n.rollback( - profile, - m.Remote("user@localhost", [], False), - True, - ) - == profile.path - ) + target_host = m.Remote("user@localhost", [], None) + assert n.rollback(profile, target_host, True) == profile.path mock_run.assert_called_with( ["nix-env", "--rollback", "-p", path], check=True, - remote=m.Remote("user@localhost", [], False), + remote=target_host, sudo=True, ) @@ -324,12 +318,9 @@ def test_rollback_temporary_profile(tmp_path: Path) -> None: sudo=False, ) + target_host = m.Remote("user@localhost", [], None) assert ( - n.rollback_temporary_profile( - m.Profile("foo", path), - m.Remote("user@localhost", [], False), - True, - ) + n.rollback_temporary_profile(m.Profile("foo", path), target_host, True) == path.parent / "foo-2083-link" ) mock_run.assert_called_with( @@ -341,7 +332,7 @@ def test_rollback_temporary_profile(tmp_path: Path) -> None: ], stdout=PIPE, check=True, - remote=m.Remote("user@localhost", [], False), + remote=target_host, sudo=True, ) @@ -406,6 +397,7 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: == "error: '--specialisation' can only be used with 'switch' and 'test'" ) + target_host = m.Remote("user@localhost", [], None) with monkeypatch.context() as mp: mp.setenv("LOCALE_ARCHIVE", "/path/to/locale") mp.setenv("PATH", "/path/to/bin") @@ -415,7 +407,7 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: Path("/path/to/config"), m.Action.TEST, sudo=True, - target_host=m.Remote("user@localhost", [], False), + target_host=target_host, install_bootloader=True, specialisation="special", ) @@ -427,7 +419,7 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: extra_env={"NIXOS_INSTALL_BOOTLOADER": "1"}, check=True, sudo=True, - remote=m.Remote("user@localhost", [], False), + remote=target_host, ) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py index 5d13954b7b7e..6987aac9283b 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_process.py @@ -2,8 +2,6 @@ from pathlib import Path from typing import Any from unittest.mock import patch -import pytest - import nixos_rebuild.models as m import nixos_rebuild.process as p @@ -19,6 +17,7 @@ def test_run(mock_run: Any) -> None: text=True, errors="surrogateescape", env=None, + input=None, ) with patch.dict(p.os.environ, {"PATH": "/path/to/bin"}, clear=True): @@ -37,12 +36,13 @@ def test_run(mock_run: Any) -> None: "PATH": "/path/to/bin", "FOO": "bar", }, + input=None, ) p.run_wrapper( ["test", "--with", "flags"], check=True, - remote=m.Remote("user@localhost", ["--ssh", "opt"], False), + remote=m.Remote("user@localhost", ["--ssh", "opt"], "password"), ) mock_run.assert_called_with( ["ssh", "--ssh", "opt", "user@localhost", "--", "test", "--with", "flags"], @@ -50,6 +50,7 @@ def test_run(mock_run: Any) -> None: text=True, errors="surrogateescape", env=None, + input=None, ) p.run_wrapper( @@ -57,17 +58,18 @@ def test_run(mock_run: Any) -> None: check=True, sudo=True, extra_env={"FOO": "bar"}, - remote=m.Remote("user@localhost", ["--ssh", "opt"], True), + remote=m.Remote("user@localhost", ["--ssh", "opt"], "password"), ) mock_run.assert_called_with( [ "ssh", - "-t", "--ssh", "opt", "user@localhost", "--", "sudo", + "--prompt=", + "--stdin", "env", "FOO=bar", "test", @@ -78,17 +80,9 @@ def test_run(mock_run: Any) -> None: env=None, text=True, errors="surrogateescape", + input="password\n", ) - with pytest.raises(AssertionError): - p.run_wrapper( - ["test", "--with", "flags"], - check=False, - allow_tty=True, - remote=m.Remote("user@localhost", [], False), - capture_output=True, - ) - def test_remote_from_name(monkeypatch: Any, tmpdir: Path) -> None: monkeypatch.setenv("NIX_SSHOPTS", "") @@ -102,23 +96,26 @@ def test_remote_from_name(monkeypatch: Any, tmpdir: Path) -> None: "-o", "ControlPersist=60", ], - tty=False, + sudo_password=None, ) - monkeypatch.setenv("NIX_SSHOPTS", "-f foo -b bar") - assert m.Remote.from_arg("user@localhost", True, tmpdir) == m.Remote( - "user@localhost", - opts=[ - "-f", - "foo", - "-b", - "bar", - "-o", - "ControlMaster=auto", - "-o", - f"ControlPath={tmpdir / "ssh-%n"}", - "-o", - "ControlPersist=60", - ], - tty=True, - ) + # get_qualified_name doesn't work because getpass is aliased to another + # function + with patch(f"{p.__name__}.getpass", return_value="password"): + monkeypatch.setenv("NIX_SSHOPTS", "-f foo -b bar") + assert m.Remote.from_arg("user@localhost", True, tmpdir) == m.Remote( + "user@localhost", + opts=[ + "-f", + "foo", + "-b", + "bar", + "-o", + "ControlMaster=auto", + "-o", + f"ControlPath={tmpdir / "ssh-%n"}", + "-o", + "ControlPersist=60", + ], + sudo_password="password", + ) From 0479ef41062f6c42e683ba19ef624d2b8dcb82d9 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Tue, 26 Nov 2024 16:56:49 +0000 Subject: [PATCH 020/166] nixos-rebuild-ng: remove explicit check for git and instead check exception --- .../nixos-rebuild-ng/src/nixos_rebuild/nix.py | 22 +++++++++---------- .../nixos-rebuild-ng/src/tests/test_main.py | 3 +-- .../ni/nixos-rebuild-ng/src/tests/test_nix.py | 3 +-- 3 files changed, 12 insertions(+), 16 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py index 13e6e4024443..5ba29216b580 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py @@ -1,5 +1,4 @@ import os -import shutil from datetime import datetime from pathlib import Path from subprocess import PIPE, CalledProcessError @@ -96,20 +95,19 @@ def get_nixpkgs_rev(nixpkgs_path: Path | None) -> str | None: if not nixpkgs_path: return None - # Git is not included in the closure for nixos-rebuild so we need to check - if not shutil.which("git"): + try: + # Get current revision + r = run_wrapper( + ["git", "-C", nixpkgs_path, "rev-parse", "--short", "HEAD"], + check=False, + stdout=PIPE, + ) + except FileNotFoundError: + # Git is not included in the closure so we need to check info(f"warning: Git not found; cannot figure out revision of '{nixpkgs_path}'") return None - # Get current revision - r = run_wrapper( - ["git", "-C", nixpkgs_path, "rev-parse", "--short", "HEAD"], - check=False, - stdout=PIPE, - ) - rev = r.stdout.strip() - - if rev: + if rev := r.stdout.strip(): # Check if repo is dirty if run_wrapper( ["git", "-C", nixpkgs_path, "diff", "--quiet"], diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py index 09ade9008ac2..c3aa97676129 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py @@ -74,8 +74,7 @@ def test_parse_args() -> None: @patch.dict(nr.process.os.environ, {}, clear=True) @patch(get_qualified_name(nr.process.subprocess.run), autospec=True) -@patch(get_qualified_name(nr.nix.shutil.which), autospec=True, return_value="/bin/git") -def test_execute_nix_boot(mock_which: Any, mock_run: Any, tmp_path: Path) -> None: +def test_execute_nix_boot(mock_run: Any, tmp_path: Path) -> None: nixpkgs_path = tmp_path / "nixpkgs" nixpkgs_path.mkdir() config_path = tmp_path / "test" diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py index fd58a050eec8..ac70bf00dfe8 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py @@ -57,8 +57,7 @@ def test_edit(mock_run: Any, monkeypatch: Any, tmpdir: Any) -> None: mock_run.assert_called_with(["editor", default_nix], check=False) -@patch(get_qualified_name(n.shutil.which), autospec=True, return_value="/bin/git") -def test_get_nixpkgs_rev(mock_which: Any) -> None: +def test_get_nixpkgs_rev() -> None: assert n.get_nixpkgs_rev(None) is None path = Path("/path/to/nix") From 088785adf843622e9beb60a8e4548e36c15111f7 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Tue, 26 Nov 2024 17:14:24 +0000 Subject: [PATCH 021/166] nixos-rebuild-ng: split parser_args in get_parser --- .../src/nixos_rebuild/__init__.py | 22 ++++++++++--------- 1 file changed, 12 insertions(+), 10 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py index 5ad716c03f6f..d8a0fb4d97d1 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py @@ -29,7 +29,7 @@ from .utils import flags_to_dict, info VERBOSE = 0 -def parse_args(argv: list[str]) -> argparse.Namespace: +def get_parser() -> argparse.ArgumentParser: parser = argparse.ArgumentParser( prog="nixos-rebuild", description="Reconfigure a NixOS machine", @@ -92,8 +92,16 @@ def parse_args(argv: list[str]) -> argparse.Namespace: copy_group = parser.add_argument_group("nix-copy-closure flags") copy_group.add_argument("--use-substitutes", "-s", action="store_true") + return parser + + +def parse_args(argv: list[str]) -> argparse.Namespace: + parser = get_parser() args = parser.parse_args(argv[1:]) + def parser_warn(msg): + info(f"{parser.prog}: warning: {msg}") + global VERBOSE # This flag affects both nix and this script VERBOSE = args.verbose @@ -107,23 +115,17 @@ def parse_args(argv: list[str]) -> argparse.Namespace: # TODO: use deprecated=True in Python >=3.13 if args.install_grub: - info( - f"{parser.prog}: warning: --install-grub deprecated, use --install-bootloader instead" - ) + parser_warn("--install-grub deprecated, use --install-bootloader instead") args.install_bootloader = True # TODO: use deprecated=True in Python >=3.13 if args.use_remote_sudo: - info( - f"{parser.prog}: warning: --use-remote-sudo deprecated, use --sudo instead" - ) + parser_warn("--use-remote-sudo deprecated, use --sudo instead") args.sudo = True # TODO: use deprecated=True in Python >=3.13 if args.no_ssh_tty: - info( - f"{parser.prog}: warning: --no-ssh-tty deprecated, SSH's pseudo-TTY is never used anymore" - ) + parser_warn("--no-ssh-tty deprecated, SSH's pseudo-TTY is never used anymore") if args.action == Action.EDIT.value and (args.file or args.attr): parser.error("--file and --attr are not supported with 'edit'") From 3a080abf135ab3b72bb7e4e33bf1a8819c37408c Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Tue, 26 Nov 2024 20:12:21 +0000 Subject: [PATCH 022/166] nixos-rebuild-ng: import nix module instead of each individual function --- .../src/nixos_rebuild/__init__.py | 49 +++++++------------ 1 file changed, 18 insertions(+), 31 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py index d8a0fb4d97d1..a9a7d4d2bef3 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py @@ -8,21 +8,8 @@ from subprocess import run from tempfile import TemporaryDirectory from typing import assert_never +from . import nix from .models import Action, Flake, NRError, Profile -from .nix import ( - copy_closure, - edit, - find_file, - get_nixpkgs_rev, - list_generations, - nixos_build, - nixos_build_flake, - rollback, - rollback_temporary_profile, - set_profile, - switch_to_configuration, - upgrade_channels, -) from .process import Remote, cleanup_ssh from .utils import flags_to_dict, info @@ -206,7 +193,7 @@ def execute(argv: list[str]) -> None: flake = Flake.from_arg(args.flake, target_host) if args.upgrade or args.upgrade_all: - upgrade_channels(bool(args.upgrade_all)) + nix.upgrade_channels(bool(args.upgrade_all)) action = Action(args.action) # Only run shell scripts from the Nixpkgs tree if the action is @@ -216,8 +203,8 @@ def execute(argv: list[str]) -> None: # untrusted tree. can_run = action in (Action.SWITCH, Action.BOOT, Action.TEST) if can_run and not flake: - nixpkgs_path = find_file("nixpkgs", **build_flags) - rev = get_nixpkgs_rev(nixpkgs_path) + nixpkgs_path = nix.find_file("nixpkgs", **build_flags) + rev = nix.get_nixpkgs_rev(nixpkgs_path) if nixpkgs_path and rev: (nixpkgs_path / ".version-suffix").write_text(rev) @@ -225,26 +212,26 @@ def execute(argv: list[str]) -> None: case Action.SWITCH | Action.BOOT: info("building the system configuration...") if args.rollback: - path_to_config = rollback(profile, target_host, sudo=args.sudo) + path_to_config = nix.rollback(profile, target_host, sudo=args.sudo) else: if flake: - path_to_config = nixos_build_flake( + path_to_config = nix.nixos_build_flake( "toplevel", flake, no_link=True, **flake_build_flags, ) else: - path_to_config = nixos_build( + path_to_config = nix.nixos_build( "system", args.attr, args.file, no_out_link=True, **build_flags, ) - copy_closure(path_to_config, target_host, **copy_flags) - set_profile(profile, path_to_config, target_host, sudo=args.sudo) - switch_to_configuration( + nix.copy_closure(path_to_config, target_host, **copy_flags) + nix.set_profile(profile, path_to_config, target_host, sudo=args.sudo) + nix.switch_to_configuration( path_to_config, action, target_host, @@ -258,7 +245,7 @@ def execute(argv: list[str]) -> None: if args.rollback: if action not in (Action.TEST, Action.BUILD): raise NRError(f"--rollback is incompatible with '{action}'") - maybe_path_to_config = rollback_temporary_profile( + maybe_path_to_config = nix.rollback_temporary_profile( profile, target_host, sudo=args.sudo, @@ -268,7 +255,7 @@ def execute(argv: list[str]) -> None: else: raise NRError("could not find previous generation") elif flake: - path_to_config = nixos_build_flake( + path_to_config = nix.nixos_build_flake( "toplevel", flake, keep_going=True, @@ -276,7 +263,7 @@ def execute(argv: list[str]) -> None: **flake_build_flags, ) else: - path_to_config = nixos_build( + path_to_config = nix.nixos_build( "system", args.attr, args.file, @@ -285,7 +272,7 @@ def execute(argv: list[str]) -> None: **build_flags, ) if action in (Action.TEST, Action.DRY_ACTIVATE): - switch_to_configuration( + nix.switch_to_configuration( path_to_config, action, target_host, @@ -296,14 +283,14 @@ def execute(argv: list[str]) -> None: info("building the system configuration...") attr = "vm" if action == Action.BUILD_VM else "vmWithBootLoader" if flake: - path_to_config = nixos_build_flake( + path_to_config = nix.nixos_build_flake( attr, flake, keep_going=True, **flake_build_flags, ) else: - path_to_config = nixos_build( + path_to_config = nix.nixos_build( attr, args.attr, args.file, @@ -313,11 +300,11 @@ def execute(argv: list[str]) -> None: vm_path = next(path_to_config.glob("bin/run-*-vm"), "./result/bin/run-*-vm") print(f"Done. The virtual machine can be started by running '{vm_path}'") case Action.EDIT: - edit(flake, **flake_build_flags) + nix.edit(flake, **flake_build_flags) case Action.DRY_RUN: assert False, "DRY_RUN should be a DRY_BUILD alias" case Action.LIST_GENERATIONS: - generations = list_generations(profile) + generations = nix.list_generations(profile) if args.json: print(json.dumps(generations, indent=2)) else: From 3ef018f5e3e871b388e4a4af6e929a88d18aae71 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Tue, 26 Nov 2024 22:08:27 +0000 Subject: [PATCH 023/166] nixos-rebuild-ng: set process.run_wrapper check=True by default --- .../nixos-rebuild-ng/src/nixos_rebuild/models.py | 1 - .../ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py | 10 ++-------- .../src/nixos_rebuild/process.py | 16 ++++++++-------- .../ni/nixos-rebuild-ng/src/tests/test_nix.py | 13 ------------- 4 files changed, 10 insertions(+), 30 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py index 6fed37cd53ff..51cee3b7c517 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py @@ -74,7 +74,6 @@ class Flake: try: return run_wrapper( ["uname", "-n"], - check=True, capture_output=True, remote=target_host, ).stdout.strip() diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py index 5ba29216b580..f0c328cff4c0 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py @@ -36,7 +36,6 @@ def copy_closure( host.host, closure, ], - check=True, extra_env={"NIX_SSHOPTS": " ".join(host.opts)}, ) @@ -171,7 +170,6 @@ def get_generations( r = run_wrapper( ["nix-env", "-p", profile.path, "--list-generations"], stdout=PIPE, - check=True, remote=target_host, sudo=sudo, ) @@ -216,7 +214,6 @@ def list_generations(profile: Profile) -> list[GenerationJson]: configuration_revision = run_wrapper( [generation_path / "sw/bin/nixos-version", "--configuration-revision"], capture_output=True, - check=True, ).stdout.strip() except (CalledProcessError, IOError): configuration_revision = "Unknown" @@ -260,7 +257,7 @@ def nixos_build( else: run_args = ["nix-build", "", "--attr", attr] run_args += dict_to_flags(nix_flags) - r = run_wrapper(run_args, check=True, stdout=PIPE) + r = run_wrapper(run_args, stdout=PIPE) return Path(r.stdout.strip()) @@ -281,7 +278,7 @@ def nixos_build_flake( f"{flake}.config.system.build.{attr}", *dict_to_flags(flake_flags), ] - r = run_wrapper(run_args, check=True, stdout=PIPE) + r = run_wrapper(run_args, stdout=PIPE) return Path(r.stdout.strip()) @@ -289,7 +286,6 @@ def rollback(profile: Profile, target_host: Remote | None, sudo: bool) -> Path: "Rollback Nix profile, like one created by `nixos-rebuild switch`." run_wrapper( ["nix-env", "--rollback", "-p", profile.path], - check=True, remote=target_host, sudo=sudo, ) @@ -329,7 +325,6 @@ def set_profile( "Set a path as the current active Nix profile." run_wrapper( ["nix-env", "-p", profile.path, "--set", path_to_config], - check=True, remote=target_host, sudo=sudo, ) @@ -361,7 +356,6 @@ def switch_to_configuration( run_wrapper( [path_to_config / "bin/switch-to-configuration", str(action)], extra_env={"NIXOS_INSTALL_BOOTLOADER": "1" if install_bootloader else "0"}, - check=True, remote=target_host, sudo=sudo, ) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py index 2b23e88a2dbc..e53f46ff8626 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py @@ -8,13 +8,6 @@ from pathlib import Path from typing import Self, Sequence, TypedDict, Unpack -# Not exhaustive, but we can always extend it later. -class RunKwargs(TypedDict, total=False): - capture_output: bool - stderr: int | None - stdout: int | None - - @dataclass(frozen=True) class Remote: host: str @@ -46,6 +39,13 @@ class Remote: return None +# Not exhaustive, but we can always extend it later. +class RunKwargs(TypedDict, total=False): + capture_output: bool + stderr: int | None + stdout: int | None + + def cleanup_ssh(tmp_dir: Path) -> None: "Close SSH ControlMaster connection." for ctrl in tmp_dir.glob("ssh-*"): @@ -55,7 +55,7 @@ def cleanup_ssh(tmp_dir: Path) -> None: def run_wrapper( args: Sequence[str | bytes | os.PathLike[str] | os.PathLike[bytes]], *, - check: bool, # make it explicit so we always know if the code is handling errors + check: bool = True, extra_env: dict[str, str] | None = None, remote: Remote | None = None, sudo: bool = False, diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py index ac70bf00dfe8..8234f0ff98f9 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py @@ -22,7 +22,6 @@ def test_copy_closure(mock_run: Any) -> None: n.copy_closure(closure, target_host) mock_run.assert_called_with( ["nix-copy-closure", "--to", "user@host", closure], - check=True, extra_env={"NIX_SSHOPTS": "--ssh opt"}, ) @@ -220,7 +219,6 @@ def test_nixos_build_flake(mock_run: Any) -> None: "--nix-flag", "foo", ], - check=True, stdout=PIPE, ) @@ -234,28 +232,24 @@ def test_nixos_build(mock_run: Any, monkeypatch: Any) -> None: assert n.nixos_build("attr", None, None, nix_flag="foo") == Path("/path/to/file") mock_run.assert_called_with( ["nix-build", "", "--attr", "attr", "--nix-flag", "foo"], - check=True, stdout=PIPE, ) n.nixos_build("attr", "preAttr", "file") mock_run.assert_called_with( ["nix-build", "file", "--attr", "preAttr.attr"], - check=True, stdout=PIPE, ) n.nixos_build("attr", None, "file", no_out_link=True) mock_run.assert_called_with( ["nix-build", "file", "--attr", "attr", "--no-out-link"], - check=True, stdout=PIPE, ) n.nixos_build("attr", "preAttr", None, no_out_link=False, keep_going=True) mock_run.assert_called_with( ["nix-build", "default.nix", "--attr", "preAttr.attr", "--keep-going"], - check=True, stdout=PIPE, ) @@ -270,7 +264,6 @@ def test_rollback(mock_run: Any, tmp_path: Path) -> None: assert n.rollback(profile, None, False) == profile.path mock_run.assert_called_with( ["nix-env", "--rollback", "-p", path], - check=True, remote=None, sudo=False, ) @@ -279,7 +272,6 @@ def test_rollback(mock_run: Any, tmp_path: Path) -> None: assert n.rollback(profile, target_host, True) == profile.path mock_run.assert_called_with( ["nix-env", "--rollback", "-p", path], - check=True, remote=target_host, sudo=True, ) @@ -312,7 +304,6 @@ def test_rollback_temporary_profile(tmp_path: Path) -> None: "--list-generations", ], stdout=PIPE, - check=True, remote=None, sudo=False, ) @@ -330,7 +321,6 @@ def test_rollback_temporary_profile(tmp_path: Path) -> None: "--list-generations", ], stdout=PIPE, - check=True, remote=target_host, sudo=True, ) @@ -353,7 +343,6 @@ def test_set_profile(mock_run: Any) -> None: mock_run.assert_called_with( ["nix-env", "-p", profile_path, "--set", config_path], - check=True, remote=None, sudo=False, ) @@ -378,7 +367,6 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: mock_run.assert_called_with( [profile_path / "bin/switch-to-configuration", "switch"], extra_env={"NIXOS_INSTALL_BOOTLOADER": "0"}, - check=True, sudo=False, remote=None, ) @@ -416,7 +404,6 @@ def test_switch_to_configuration(mock_run: Any, monkeypatch: Any) -> None: "test", ], extra_env={"NIXOS_INSTALL_BOOTLOADER": "1"}, - check=True, sudo=True, remote=target_host, ) From a848fde40e15114c70c9d2a5e97d94e4fa4605ef Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Fri, 22 Nov 2024 00:31:11 +0100 Subject: [PATCH 024/166] nagstamon: 3.14.0 -> 3.16.2 Co-authored-by: liberodark Diff: https://github.com/HenriWahl/Nagstamon/compare/v3.14.0...v3.16.2 Changelog: https://github.com/HenriWahl/Nagstamon/releases/tag/v3.16.2 --- pkgs/by-name/na/nagstamon/package.nix | 70 ++++++++++++++++++--------- 1 file changed, 47 insertions(+), 23 deletions(-) diff --git a/pkgs/by-name/na/nagstamon/package.nix b/pkgs/by-name/na/nagstamon/package.nix index f09082bdd197..f25d5e4d68a5 100644 --- a/pkgs/by-name/na/nagstamon/package.nix +++ b/pkgs/by-name/na/nagstamon/package.nix @@ -1,43 +1,67 @@ { lib, - fetchurl, + fetchFromGitHub, python3Packages, + qt6Packages, }: python3Packages.buildPythonApplication rec { pname = "nagstamon"; - version = "3.14.0"; + version = "3.16.2"; - src = fetchurl { - url = "https://github.com/HenriWahl/Nagstamon/archive/refs/tags/v${version}.tar.gz"; - sha256 = "sha256-9RxQ/rfvoyjSUsY4tmAkBdVQqZYi3X6PBzQYFIeenzA="; + src = fetchFromGitHub { + owner = "HenriWahl"; + repo = "Nagstamon"; + rev = "refs/tags/v${version}"; + hash = "sha256-9w8ux+AeSg0vDhnk28/2eCE2zYLvAjD7mB0pJBMFs2I="; }; - # Test assumes darwin - doCheck = false; - build-system = with python3Packages; [ setuptools ]; - dependencies = with python3Packages; [ - configparser - pyqt6 - psutil - requests - beautifulsoup4 - keyring - requests-kerberos - lxml - dbus-python - python-dateutil - pysocks + + nativeBuildInputs = [ qt6Packages.wrapQtAppsHook ]; + + buildInputs = [ + qt6Packages.qtmultimedia + qt6Packages.qtsvg ]; - meta = with lib; { + dontWrapQtApps = true; + + preFixup = '' + makeWrapperArgs+=("''${qtWrapperArgs[@]}") + ''; + + dependencies = with python3Packages; [ + arrow + beautifulsoup4 + configparser + dbus-python + keyring + lxml + psutil + pyqt6 + pysocks + python-dateutil + requests + requests-kerberos + ]; + + nativeCheckInputs = with python3Packages; [ + pylint + pytestCheckHook + ]; + + meta = { description = "Status monitor for the desktop"; homepage = "https://nagstamon.de/"; - license = licenses.gpl2Plus; - maintainers = with maintainers; [ + changelog = "https://github.com/HenriWahl/Nagstamon/releases/tag/v${version}"; + license = lib.licenses.gpl2Plus; + maintainers = with lib.maintainers; [ pSub liberodark ]; + mainProgram = "nagstamon.py"; + # NameError: name 'bdist_rpm_options' is not defined. Did you mean: 'bdist_mac_options'? + badPlatforms = [ lib.systems.inspect.patterns.isDarwin ]; }; } From 287518360aaade3943e91d14b4bc9f806cdc73c6 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Wed, 27 Nov 2024 10:54:25 +0000 Subject: [PATCH 025/166] nixos-rebuild-ng: validate NIX_SSHOPTS --- .../src/nixos_rebuild/__init__.py | 2 +- .../src/nixos_rebuild/process.py | 48 +++++++++++++------ 2 files changed, 34 insertions(+), 16 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py index a9a7d4d2bef3..47ca3f5f030c 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py @@ -112,7 +112,7 @@ def parse_args(argv: list[str]) -> argparse.Namespace: # TODO: use deprecated=True in Python >=3.13 if args.no_ssh_tty: - parser_warn("--no-ssh-tty deprecated, SSH's pseudo-TTY is never used anymore") + parser_warn("--no-ssh-tty deprecated, SSH's TTY is never used anymore") if args.action == Action.EDIT.value and (args.file or args.attr): parser.error("--file and --attr are not supported with 'edit'") diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py index e53f46ff8626..db470ee5753c 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/process.py @@ -7,6 +7,8 @@ from getpass import getpass from pathlib import Path from typing import Self, Sequence, TypedDict, Unpack +from .utils import info + @dataclass(frozen=True) class Remote: @@ -21,23 +23,39 @@ class Remote: ask_sudo_password: bool | None, tmp_dir: Path, ) -> Self | None: - if host: - opts = os.getenv("NIX_SSHOPTS", "").split() + [ - # SSH ControlMaster flags, allow for faster re-connection - "-o", - "ControlMaster=auto", - "-o", - f"ControlPath={tmp_dir / "ssh-%n"}", - "-o", - "ControlPersist=60", - ] - sudo_password = None - if ask_sudo_password: - sudo_password = getpass(f"[sudo] password for {host}: ") - return cls(host, opts, sudo_password) - else: + if not host: return None + opts = os.getenv("NIX_SSHOPTS", "").split() + cls._validate_opts(opts, ask_sudo_password) + opts += [ + # SSH ControlMaster flags, allow for faster re-connection + "-o", + "ControlMaster=auto", + "-o", + f"ControlPath={tmp_dir / "ssh-%n"}", + "-o", + "ControlPersist=60", + ] + sudo_password = None + if ask_sudo_password: + sudo_password = getpass(f"[sudo] password for {host}: ") + return cls(host, opts, sudo_password) + + @staticmethod + def _validate_opts(opts: list[str], ask_sudo_password: bool | None) -> None: + for o in opts: + if o in ["-t", "-tt", "RequestTTY=yes", "RequestTTY=force"]: + info( + f"warning: detected option '{o}' in NIX_SSHOPTS. SSH's TTY " + + "may cause issues, it is recommended to remove this option" + ) + if not ask_sudo_password: + info( + "If you want to prompt for sudo password use " + + "'--ask-sudo-password' option instead" + ) + # Not exhaustive, but we can always extend it later. class RunKwargs(TypedDict, total=False): From 5cbc6f562383608b2f8884b75b8e848bcab82136 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Wed, 27 Nov 2024 12:48:06 +0000 Subject: [PATCH 026/166] nixos-rebuild-ng: use argparse groups to group nix flags --- .../src/nixos_rebuild/__init__.py | 190 ++++++++---------- .../src/nixos_rebuild/utils.py | 6 - .../nixos-rebuild-ng/src/tests/test_main.py | 6 +- .../nixos-rebuild-ng/src/tests/test_utils.py | 22 -- 4 files changed, 89 insertions(+), 135 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py index 47ca3f5f030c..2aead64c5465 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/__init__.py @@ -11,82 +11,99 @@ from typing import assert_never from . import nix from .models import Action, Flake, NRError, Profile from .process import Remote, cleanup_ssh -from .utils import flags_to_dict, info +from .utils import info VERBOSE = 0 -def get_parser() -> argparse.ArgumentParser: - parser = argparse.ArgumentParser( +def get_parser() -> tuple[argparse.ArgumentParser, dict[str, argparse.ArgumentParser]]: + common_flags = argparse.ArgumentParser(add_help=False) + common_flags.add_argument("--verbose", "-v", action="count", default=0) + common_flags.add_argument("--max-jobs", "-j") + common_flags.add_argument("--cores") + common_flags.add_argument("--log-format") + common_flags.add_argument("--keep-going", "-k", action="store_true") + common_flags.add_argument("--keep-failed", "-K", action="store_true") + common_flags.add_argument("--fallback", action="store_true") + common_flags.add_argument("--repair", action="store_true") + common_flags.add_argument("--option", nargs=2) + + common_build_flags = argparse.ArgumentParser(add_help=False) + common_build_flags.add_argument("--include", "-I") + common_build_flags.add_argument("--quiet", action="store_true") + common_build_flags.add_argument("--print-build-logs", "-L", action="store_true") + common_build_flags.add_argument("--show-trace", action="store_true") + + flake_build_flags = argparse.ArgumentParser(add_help=False) + flake_build_flags.add_argument("--accept-flake-config", action="store_true") + flake_build_flags.add_argument("--refresh", action="store_true") + flake_build_flags.add_argument("--impure", action="store_true") + flake_build_flags.add_argument("--offline", action="store_true") + flake_build_flags.add_argument("--no-net", action="store_true") + flake_build_flags.add_argument("--recreate-lock-file", action="store_true") + flake_build_flags.add_argument("--no-update-lock-file", action="store_true") + flake_build_flags.add_argument("--no-write-lock-file", action="store_true") + flake_build_flags.add_argument("--no-registries", action="store_true") + flake_build_flags.add_argument("--commit-lock-file", action="store_true") + flake_build_flags.add_argument("--update-input") + flake_build_flags.add_argument("--override-input", nargs=2) + + classic_build_flags = argparse.ArgumentParser(add_help=False) + classic_build_flags.add_argument("--no-build-output", "-Q", action="store_true") + + copy_flags = argparse.ArgumentParser(add_help=False) + copy_flags.add_argument("--use-substitutes", "-s", action="store_true") + + sub_parsers = { + "common_flags": common_flags, + "common_build_flags": common_build_flags, + "flake_build_flags": flake_build_flags, + "classic_build_flags": classic_build_flags, + "copy_flags": copy_flags, + } + + main_parser = argparse.ArgumentParser( prog="nixos-rebuild", + parents=list(sub_parsers.values()), description="Reconfigure a NixOS machine", add_help=False, allow_abbrev=False, ) - parser.add_argument("--help", "-h", action="store_true") - parser.add_argument("--file", "-f") - parser.add_argument("--attr", "-A") - parser.add_argument("--flake", nargs="?", const=True) - parser.add_argument("--no-flake", dest="flake", action="store_false") - parser.add_argument("--install-bootloader", action="store_true") - parser.add_argument("--install-grub", action="store_true") # deprecated - parser.add_argument("--profile-name", "-p", default="system") - parser.add_argument("--specialisation", "-c") - parser.add_argument("--rollback", action="store_true") - parser.add_argument("--upgrade", action="store_true") - parser.add_argument("--upgrade-all", action="store_true") - parser.add_argument("--json", action="store_true") - parser.add_argument("--sudo", action="store_true") - parser.add_argument("--ask-sudo-password", action="store_true") - parser.add_argument("--use-remote-sudo", action="store_true") # deprecated - parser.add_argument("--no-ssh-tty", action="store_true") # deprecated + main_parser.add_argument("--help", "-h", action="store_true") + main_parser.add_argument("--file", "-f") + main_parser.add_argument("--attr", "-A") + main_parser.add_argument("--flake", nargs="?", const=True) + main_parser.add_argument("--no-flake", dest="flake", action="store_false") + main_parser.add_argument("--install-bootloader", action="store_true") + main_parser.add_argument("--install-grub", action="store_true") # deprecated + main_parser.add_argument("--profile-name", "-p", default="system") + main_parser.add_argument("--specialisation", "-c") + main_parser.add_argument("--rollback", action="store_true") + main_parser.add_argument("--upgrade", action="store_true") + main_parser.add_argument("--upgrade-all", action="store_true") + main_parser.add_argument("--json", action="store_true") + main_parser.add_argument("--sudo", action="store_true") + main_parser.add_argument("--ask-sudo-password", action="store_true") + main_parser.add_argument("--use-remote-sudo", action="store_true") # deprecated + main_parser.add_argument("--no-ssh-tty", action="store_true") # deprecated # parser.add_argument("--build-host") # TODO - parser.add_argument("--target-host") - parser.add_argument("--verbose", "-v", action="count", default=0) - parser.add_argument("action", choices=Action.values(), nargs="?") + main_parser.add_argument("--target-host") + main_parser.add_argument("action", choices=Action.values(), nargs="?") - common_group = parser.add_argument_group("nix flags") - common_group.add_argument("--include", "-I") - common_group.add_argument("--max-jobs", "-j") - common_group.add_argument("--cores") - common_group.add_argument("--log-format") - common_group.add_argument("--quiet", action="store_true") - common_group.add_argument("--print-build-logs", "-L", action="store_true") - common_group.add_argument("--show-trace", action="store_true") - common_group.add_argument("--keep-going", "-k", action="store_true") - common_group.add_argument("--keep-failed", "-K", action="store_true") - common_group.add_argument("--fallback", action="store_true") - common_group.add_argument("--repair", action="store_true") - common_group.add_argument("--option", nargs=2) - - nix_group = parser.add_argument_group("nix classic flags") - nix_group.add_argument("--no-build-output", "-Q", action="store_true") - - flake_group = parser.add_argument_group("nix flakes flags") - flake_group.add_argument("--accept-flake-config", action="store_true") - flake_group.add_argument("--refresh", action="store_true") - flake_group.add_argument("--impure", action="store_true") - flake_group.add_argument("--offline", action="store_true") - flake_group.add_argument("--no-net", action="store_true") - flake_group.add_argument("--recreate-lock-file", action="store_true") - flake_group.add_argument("--no-update-lock-file", action="store_true") - flake_group.add_argument("--no-write-lock-file", action="store_true") - flake_group.add_argument("--no-registries", action="store_true") - flake_group.add_argument("--commit-lock-file", action="store_true") - flake_group.add_argument("--update-input") - flake_group.add_argument("--override-input", nargs=2) - - copy_group = parser.add_argument_group("nix-copy-closure flags") - copy_group.add_argument("--use-substitutes", "-s", action="store_true") - - return parser + return main_parser, sub_parsers -def parse_args(argv: list[str]) -> argparse.Namespace: - parser = get_parser() +def parse_args( + argv: list[str], +) -> tuple[argparse.Namespace, dict[str, argparse.Namespace]]: + parser, sub_parsers = get_parser() args = parser.parse_args(argv[1:]) + args_groups = { + group: parser.parse_known_args(argv[1:])[0] + for group, parser in sub_parsers.items() + } - def parser_warn(msg): + def parser_warn(msg: str) -> None: info(f"{parser.prog}: warning: {msg}") global VERBOSE @@ -134,54 +151,17 @@ def parse_args(argv: list[str]) -> argparse.Namespace: r = run(["man", "8", "nixos-rebuild"], check=False) parser.exit(r.returncode) - return args + return args, args_groups def execute(argv: list[str]) -> None: - args = parse_args(argv) + args, args_groups = parse_args(argv) - common_flags = flags_to_dict( - args, - [ - "max_jobs", - "cores", - "log_format", - "keep_going", - "keep_failed", - "fallback", - "repair", - "verbose", - "option", - ], - ) - common_build_flags = common_flags | flags_to_dict( - args, - [ - "include", - "quiet", - "print_build_logs", - "show_trace", - ], - ) - build_flags = common_build_flags | flags_to_dict(args, ["no_build_output"]) - flake_build_flags = common_build_flags | flags_to_dict( - args, - [ - "accept_flake_config", - "refresh", - "impure", - "offline", - "no_net", - "recreate_lock_file", - "no_update_lock_file", - "no_write_lock_file", - "no_registries", - "commit_lock_file", - "update_input", - "override_input", - ], - ) - copy_flags = common_flags | flags_to_dict(args, ["use_substitutes"]) + common_flags = vars(args_groups["common_flags"]) + common_build_flags = common_flags | vars(args_groups["common_build_flags"]) + build_flags = common_build_flags | vars(args_groups["classic_build_flags"]) + flake_build_flags = common_build_flags | vars(args_groups["flake_build_flags"]) + copy_flags = common_flags | vars(args_groups["copy_flags"]) # Will be cleaned up on exit automatically. tmpdir = TemporaryDirectory(prefix="nixos-rebuild.") diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/utils.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/utils.py index 3c2f9e47bc48..8d4f128075d4 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/utils.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/utils.py @@ -1,4 +1,3 @@ -import argparse import sys from functools import partial from typing import TypeAlias @@ -26,8 +25,3 @@ def dict_to_flags(d: dict[str, Args]) -> list[str]: for v in value: flags.append(v) return flags - - -def flags_to_dict(args: argparse.Namespace, keys: list[str]) -> dict[str, Args]: - d = vars(args) - return {k: d[k] for k in keys} diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py index c3aa97676129..e3bb1ba8f6e7 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py @@ -31,7 +31,7 @@ def test_parse_args() -> None: nr.parse_args(["nixos-rebuild", "edit", "--attr", "attr"]) assert e.value.code == 2 - r1 = nr.parse_args( + r1, g1 = nr.parse_args( [ "nixos-rebuild", "switch", @@ -50,8 +50,9 @@ def test_parse_args() -> None: assert r1.profile_name == "system" assert r1.action == "switch" assert r1.option == ["foo", "bar"] + assert g1["common_flags"].option == ["foo", "bar"] - r2 = nr.parse_args( + r2, g2 = nr.parse_args( [ "nixos-rebuild", "dry-run", @@ -70,6 +71,7 @@ def test_parse_args() -> None: assert r2.action == "dry-build" assert r2.file == "foo" assert r2.attr == "bar" + assert g2["common_flags"].verbose == 3 @patch.dict(nr.process.os.environ, {}, clear=True) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_utils.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_utils.py index 5258c7529a00..0e5eb7437f65 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_utils.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_utils.py @@ -1,5 +1,3 @@ -import argparse - import nixos_rebuild.utils as u @@ -25,23 +23,3 @@ def test_dict_to_flags() -> None: ] r2 = u.dict_to_flags({"verbose": 0, "empty_list": []}) assert r2 == [] - - -def test_flags_to_dict() -> None: - r = u.flags_to_dict( - argparse.Namespace( - test_flag_1=True, - test_flag_2=False, - test_flag_3="value", - test_flag_4=["v1", "v2"], - test_flag_5=None, - verbose=5, - ), - ["test_flag_1", "test_flag_3", "test_flag_4", "verbose"], - ) - assert r == { - "test_flag_1": True, - "test_flag_3": "value", - "test_flag_4": ["v1", "v2"], - "verbose": 5, - } From 17c011592a1a5155dddac6d7a1ebb85ec4880630 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:28 +0200 Subject: [PATCH 027/166] nixos/i18n.inputMethod.hime: remove `with lib;` --- nixos/modules/i18n/input-method/hime.nix | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/nixos/modules/i18n/input-method/hime.nix b/nixos/modules/i18n/input-method/hime.nix index baf455bd2366..b3f49c0e3057 100644 --- a/nixos/modules/i18n/input-method/hime.nix +++ b/nixos/modules/i18n/input-method/hime.nix @@ -1,12 +1,9 @@ { config, pkgs, lib, ... }: - -with lib; - let imcfg = config.i18n.inputMethod; in { - config = mkIf (imcfg.enable && imcfg.type == "hime") { + config = lib.mkIf (imcfg.enable && imcfg.type == "hime") { i18n.inputMethod.package = pkgs.hime; environment.variables = { GTK_IM_MODULE = "hime"; From 3eb92bcce7c48cb65d394cd99de680f439bc093e Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:28 +0200 Subject: [PATCH 028/166] nixos/i18n.inputMethod.ibus: remove `with lib;` --- nixos/modules/i18n/input-method/ibus.nix | 31 +++++++++++------------- 1 file changed, 14 insertions(+), 17 deletions(-) diff --git a/nixos/modules/i18n/input-method/ibus.nix b/nixos/modules/i18n/input-method/ibus.nix index 4af848c72015..7665b83e0f95 100644 --- a/nixos/modules/i18n/input-method/ibus.nix +++ b/nixos/modules/i18n/input-method/ibus.nix @@ -1,7 +1,4 @@ { config, pkgs, lib, ... }: - -with lib; - let imcfg = config.i18n.inputMethod; cfg = imcfg.ibus; @@ -9,10 +6,10 @@ let ibusEngine = lib.types.mkOptionType { name = "ibus-engine"; inherit (lib.types.package) descriptionClass merge; - check = x: (lib.types.package.check x) && (attrByPath ["meta" "isIbusEngine"] false x); + check = x: (lib.types.package.check x) && (lib.attrByPath ["meta" "isIbusEngine"] false x); }; - impanel = optionalString (cfg.panel != null) "--panel=${cfg.panel}"; + impanel = lib.optionalString (cfg.panel != null) "--panel=${cfg.panel}"; ibusAutostart = pkgs.writeTextFile { name = "autostart-ibus-daemon"; @@ -29,32 +26,32 @@ let in { imports = [ - (mkRenamedOptionModule [ "programs" "ibus" "plugins" ] [ "i18n" "inputMethod" "ibus" "engines" ]) + (lib.mkRenamedOptionModule [ "programs" "ibus" "plugins" ] [ "i18n" "inputMethod" "ibus" "engines" ]) ]; options = { i18n.inputMethod.ibus = { - engines = mkOption { - type = with types; listOf ibusEngine; + engines = lib.mkOption { + type = with lib.types; listOf ibusEngine; default = []; - example = literalExpression "with pkgs.ibus-engines; [ mozc hangul ]"; + example = lib.literalExpression "with pkgs.ibus-engines; [ mozc hangul ]"; description = let - enginesDrv = filterAttrs (const isDerivation) pkgs.ibus-engines; - engines = concatStringsSep ", " - (map (name: "`${name}`") (attrNames enginesDrv)); + enginesDrv = lib.filterAttrs (lib.const lib.isDerivation) pkgs.ibus-engines; + engines = lib.concatStringsSep ", " + (map (name: "`${name}`") (lib.attrNames enginesDrv)); in "Enabled IBus engines. Available engines are: ${engines}."; }; - panel = mkOption { - type = with types; nullOr path; + panel = lib.mkOption { + type = with lib.types; nullOr path; default = null; - example = literalExpression ''"''${pkgs.plasma5Packages.plasma-desktop}/libexec/kimpanel-ibus-panel"''; + example = lib.literalExpression ''"''${pkgs.plasma5Packages.plasma-desktop}/libexec/kimpanel-ibus-panel"''; description = "Replace the IBus panel with another panel."; }; }; }; - config = mkIf (imcfg.enable && imcfg.type == "ibus") { + config = lib.mkIf (imcfg.enable && imcfg.type == "ibus") { i18n.inputMethod.package = ibusPackage; environment.systemPackages = [ @@ -76,7 +73,7 @@ in XMODIFIERS = "@im=ibus"; }; - xdg.portal.extraPortals = mkIf config.xdg.portal.enable [ + xdg.portal.extraPortals = lib.mkIf config.xdg.portal.enable [ ibusPackage ]; }; From d5a377e94eee59903b51ad78ac3a0dab20cb29f1 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:28 +0200 Subject: [PATCH 029/166] nixos/i18n.inputMethod.nabi: remove `with lib;` --- nixos/modules/i18n/input-method/nabi.nix | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/nixos/modules/i18n/input-method/nabi.nix b/nixos/modules/i18n/input-method/nabi.nix index 0eb9a7c825c8..af01d1b0676d 100644 --- a/nixos/modules/i18n/input-method/nabi.nix +++ b/nixos/modules/i18n/input-method/nabi.nix @@ -1,11 +1,9 @@ { config, pkgs, lib, ... }: - -with lib; let imcfg = config.i18n.inputMethod; in { - config = mkIf (imcfg.enable && imcfg.type == "nabi") { + config = lib.mkIf (imcfg.enable && imcfg.type == "nabi") { i18n.inputMethod.package = pkgs.nabi; environment.variables = { From 387be4f6c369eedfa37d7e5ba97a3fc354a84682 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:29 +0200 Subject: [PATCH 030/166] nixos/i18n.inputMethod.uim: remove `with lib;` --- nixos/modules/i18n/input-method/uim.nix | 9 +++------ 1 file changed, 3 insertions(+), 6 deletions(-) diff --git a/nixos/modules/i18n/input-method/uim.nix b/nixos/modules/i18n/input-method/uim.nix index 7517dead6b05..4edc121b2ccd 100644 --- a/nixos/modules/i18n/input-method/uim.nix +++ b/nixos/modules/i18n/input-method/uim.nix @@ -1,7 +1,4 @@ { config, pkgs, lib, ... }: - -with lib; - let imcfg = config.i18n.inputMethod; cfg = imcfg.uim; @@ -10,8 +7,8 @@ in options = { i18n.inputMethod.uim = { - toolbar = mkOption { - type = types.enum [ "gtk" "gtk3" "gtk-systray" "gtk3-systray" "qt5" ]; + toolbar = lib.mkOption { + type = lib.types.enum [ "gtk" "gtk3" "gtk-systray" "gtk3-systray" "qt5" ]; default = "gtk"; example = "gtk-systray"; description = '' @@ -22,7 +19,7 @@ in }; - config = mkIf (imcfg.enable && imcfg.type == "uim") { + config = lib.mkIf (imcfg.enable && imcfg.type == "uim") { i18n.inputMethod.package = pkgs.uim; environment.variables = { From 650b7695e0b7e7ea18e547d97d3041a65ff6a170 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:30 +0200 Subject: [PATCH 031/166] nixos/assertions: remove `with lib;` --- nixos/modules/misc/assertions.nix | 11 ++++------- 1 file changed, 4 insertions(+), 7 deletions(-) diff --git a/nixos/modules/misc/assertions.nix b/nixos/modules/misc/assertions.nix index 550b3ac97f6a..489a2b8085ae 100644 --- a/nixos/modules/misc/assertions.nix +++ b/nixos/modules/misc/assertions.nix @@ -1,13 +1,10 @@ { lib, ... }: - -with lib; - { options = { - assertions = mkOption { - type = types.listOf types.unspecified; + assertions = lib.mkOption { + type = lib.types.listOf lib.types.unspecified; internal = true; default = []; example = [ { assertion = false; message = "you can't enable this for that reason"; } ]; @@ -18,10 +15,10 @@ with lib; ''; }; - warnings = mkOption { + warnings = lib.mkOption { internal = true; default = []; - type = types.listOf types.str; + type = lib.types.listOf lib.types.str; example = [ "The `foo' service is deprecated and will go away soon!" ]; description = '' This option allows modules to show warnings to users during From 4feff6c9b5b112f6eb2014115e572f23758ef162 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:30 +0200 Subject: [PATCH 032/166] nixos/crashdump: remove `with lib;` --- nixos/modules/misc/crashdump.nix | 19 ++++++++----------- 1 file changed, 8 insertions(+), 11 deletions(-) diff --git a/nixos/modules/misc/crashdump.nix b/nixos/modules/misc/crashdump.nix index b0f75d9caaa3..d67a4aa412ce 100644 --- a/nixos/modules/misc/crashdump.nix +++ b/nixos/modules/misc/crashdump.nix @@ -1,11 +1,8 @@ { config, lib, pkgs, ... }: - -with lib; - let crashdump = config.boot.crashDump; - kernelParams = concatStringsSep " " crashdump.kernelParams; + kernelParams = lib.concatStringsSep " " crashdump.kernelParams; in ###### interface @@ -13,8 +10,8 @@ in options = { boot = { crashDump = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = '' If enabled, NixOS will set up a kernel that will @@ -24,17 +21,17 @@ in It also activates the NMI watchdog. ''; }; - reservedMemory = mkOption { + reservedMemory = lib.mkOption { default = "128M"; - type = types.str; + type = lib.types.str; description = '' The amount of memory reserved for the crashdump kernel. If you choose a too high value, dmesg will mention "crashkernel reservation failed". ''; }; - kernelParams = mkOption { - type = types.listOf types.str; + kernelParams = lib.mkOption { + type = lib.types.listOf lib.types.str; default = [ "1" "boot.shell_on_fail" ]; description = '' Parameters that will be passed to the kernel kexec-ed on crash. @@ -46,7 +43,7 @@ in ###### implementation - config = mkIf crashdump.enable { + config = lib.mkIf crashdump.enable { boot = { postBootCommands = '' echo "loading crashdump kernel..."; From 0334b1bf8ebf9ed58de2b6de279bae0bd237c69b Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:30 +0200 Subject: [PATCH 033/166] nixos/label: remove `with lib;` --- nixos/modules/misc/label.nix | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-) diff --git a/nixos/modules/misc/label.nix b/nixos/modules/misc/label.nix index c7177f65a0fd..aba5ae23dc39 100644 --- a/nixos/modules/misc/label.nix +++ b/nixos/modules/misc/label.nix @@ -1,7 +1,4 @@ { config, lib, ... }: - -with lib; - let cfg = config.system.nixos; in @@ -10,8 +7,8 @@ in options.system = { - nixos.label = mkOption { - type = types.strMatching "[a-zA-Z0-9:_\\.-]*"; + nixos.label = lib.mkOption { + type = lib.types.strMatching "[a-zA-Z0-9:_\\.-]*"; description = '' NixOS version name to be used in the names of generated outputs and boot labels. @@ -43,8 +40,8 @@ in ''; }; - nixos.tags = mkOption { - type = types.listOf types.str; + nixos.tags = lib.mkOption { + type = lib.types.listOf lib.types.str; default = []; example = [ "with-xen" ]; description = '' @@ -68,9 +65,9 @@ in config = { # This is set here rather than up there so that changing it would # not rebuild the manual - system.nixos.label = mkDefault (maybeEnv "NIXOS_LABEL" - (concatStringsSep "-" ((sort (x: y: x < y) cfg.tags) - ++ [ (maybeEnv "NIXOS_LABEL_VERSION" cfg.version) ]))); + system.nixos.label = lib.mkDefault (lib.maybeEnv "NIXOS_LABEL" + (lib.concatStringsSep "-" ((lib.sort (x: y: x < y) cfg.tags) + ++ [ (lib.maybeEnv "NIXOS_LABEL_VERSION" cfg.version) ]))); }; } From 9a8512f4600d34289b197402c37f079add5835e5 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:31 +0200 Subject: [PATCH 034/166] nixos/meta: remove `with lib;` --- nixos/modules/misc/meta.nix | 29 +++++++++++++---------------- 1 file changed, 13 insertions(+), 16 deletions(-) diff --git a/nixos/modules/misc/meta.nix b/nixos/modules/misc/meta.nix index e5ab3a951537..1569662b403c 100644 --- a/nixos/modules/misc/meta.nix +++ b/nixos/modules/misc/meta.nix @@ -1,28 +1,25 @@ { lib, ... }: - -with lib; - let - maintainer = mkOptionType { + maintainer = lib.mkOptionType { name = "maintainer"; - check = email: elem email (attrValues lib.maintainers); - merge = loc: defs: listToAttrs (singleton (nameValuePair (last defs).file (last defs).value)); + check = email: lib.elem email (lib.attrValues lib.maintainers); + merge = loc: defs: lib.listToAttrs (lib.singleton (lib.nameValuePair (lib.last defs).file (lib.last defs).value)); }; - listOfMaintainers = types.listOf maintainer // { + listOfMaintainers = lib.types.listOf maintainer // { # Returns list of # { "module-file" = [ # "maintainer1 " # "maintainer2 " ]; # } merge = loc: defs: - zipAttrs - (flatten (imap1 (n: def: imap1 (m: def': + lib.zipAttrs + (lib.flatten (lib.imap1 (n: def: lib.imap1 (m: def': maintainer.merge (loc ++ ["[${toString n}-${toString m}]"]) [{ inherit (def) file; value = def'; }]) def.value) defs)); }; - docFile = types.path // { + docFile = lib.types.path // { # Returns tuples of # { file = "module location"; value = ; } merge = loc: defs: defs; @@ -33,18 +30,18 @@ in options = { meta = { - maintainers = mkOption { + maintainers = lib.mkOption { type = listOfMaintainers; internal = true; default = []; - example = literalExpression ''[ lib.maintainers.all ]''; + example = lib.literalExpression ''[ lib.maintainers.all ]''; description = '' List of maintainers of each module. This option should be defined at most once per module. ''; }; - doc = mkOption { + doc = lib.mkOption { type = docFile; internal = true; example = "./meta.chapter.md"; @@ -54,8 +51,8 @@ in ''; }; - buildDocsInSandbox = mkOption { - type = types.bool // { + buildDocsInSandbox = lib.mkOption { + type = lib.types.bool // { merge = loc: defs: defs; }; internal = true; @@ -72,5 +69,5 @@ in }; }; - meta.maintainers = singleton lib.maintainers.pierron; + meta.maintainers = lib.singleton lib.maintainers.pierron; } From b1a2522f05c23ad8795985d827c059afb367c2cf Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:31 +0200 Subject: [PATCH 035/166] nixos/fcast-receiver: remove `with lib;` --- nixos/modules/programs/fcast-receiver.nix | 15 ++++++--------- 1 file changed, 6 insertions(+), 9 deletions(-) diff --git a/nixos/modules/programs/fcast-receiver.nix b/nixos/modules/programs/fcast-receiver.nix index 2e4e6bf8b242..73e13cd1bc8d 100644 --- a/nixos/modules/programs/fcast-receiver.nix +++ b/nixos/modules/programs/fcast-receiver.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.programs.fcast-receiver; in @@ -11,20 +8,20 @@ in }; options.programs.fcast-receiver = { - enable = mkEnableOption "FCast Receiver"; - openFirewall = mkOption { - type = types.bool; + enable = lib.mkEnableOption "FCast Receiver"; + openFirewall = lib.mkOption { + type = lib.types.bool; default = false; description = '' Open ports needed for the functionality of the program. ''; }; - package = mkPackageOption pkgs "fcast-receiver" { }; + package = lib.mkPackageOption pkgs "fcast-receiver" { }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = [ cfg.package ]; - networking.firewall = mkIf cfg.openFirewall { + networking.firewall = lib.mkIf cfg.openFirewall { allowedTCPPorts = [ 46899 ]; }; }; From 236ed7869df014ce78d71e8ba57ec080e149b738 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:32 +0200 Subject: [PATCH 036/166] nixos/security.apparmor: remove `with lib;` --- nixos/modules/security/apparmor.nix | 49 ++++++++++++++--------------- 1 file changed, 23 insertions(+), 26 deletions(-) diff --git a/nixos/modules/security/apparmor.nix b/nixos/modules/security/apparmor.nix index a4b3807e4e0f..d6195d24ea8d 100644 --- a/nixos/modules/security/apparmor.nix +++ b/nixos/modules/security/apparmor.nix @@ -1,30 +1,27 @@ { config, lib, pkgs, ... }: - -with lib; - let inherit (builtins) attrNames head map match readFile; inherit (lib) types; inherit (config.environment) etc; cfg = config.security.apparmor; - mkDisableOption = name: mkEnableOption name // { + mkDisableOption = name: lib.mkEnableOption name // { default = true; example = false; }; - enabledPolicies = filterAttrs (n: p: p.enable) cfg.policies; + enabledPolicies = lib.filterAttrs (n: p: p.enable) cfg.policies; in { imports = [ - (mkRemovedOptionModule [ "security" "apparmor" "confineSUIDApplications" ] "Please use the new options: `security.apparmor.policies..enable'.") - (mkRemovedOptionModule [ "security" "apparmor" "profiles" ] "Please use the new option: `security.apparmor.policies'.") + (lib.mkRemovedOptionModule [ "security" "apparmor" "confineSUIDApplications" ] "Please use the new options: `security.apparmor.policies..enable'.") + (lib.mkRemovedOptionModule [ "security" "apparmor" "profiles" ] "Please use the new option: `security.apparmor.policies'.") apparmor/includes.nix apparmor/profiles.nix ]; options = { security.apparmor = { - enable = mkEnableOption '' + enable = lib.mkEnableOption '' the AppArmor Mandatory Access Control system. If you're enabling this module on a running system, @@ -41,7 +38,7 @@ in Enable [](#opt-security.apparmor.killUnconfinedConfinables) if you want this service to do such killing by sending a `SIGTERM` to those running processes''; - policies = mkOption { + policies = lib.mkOption { description = '' AppArmor policies. ''; @@ -49,7 +46,7 @@ in options = { enable = mkDisableOption "loading of the profile into the kernel"; enforce = mkDisableOption "enforcing of the policy or only complain in the logs"; - profile = mkOption { + profile = lib.mkOption { description = "The policy of the profile."; type = types.lines; apply = pkgs.writeText name; @@ -58,28 +55,28 @@ in })); default = {}; }; - includes = mkOption { + includes = lib.mkOption { type = types.attrsOf types.lines; default = {}; description = '' List of paths to be added to AppArmor's searched paths when resolving `include` directives. ''; - apply = mapAttrs pkgs.writeText; + apply = lib.mapAttrs pkgs.writeText; }; - packages = mkOption { + packages = lib.mkOption { type = types.listOf types.package; default = []; description = "List of packages to be added to AppArmor's include path"; }; - enableCache = mkEnableOption '' + enableCache = lib.mkEnableOption '' caching of AppArmor policies in `/var/cache/apparmor/`. Beware that AppArmor policies almost always contain Nix store paths, and thus produce at each change of these paths a new cached version accumulating in the cache''; - killUnconfinedConfinables = mkEnableOption '' + killUnconfinedConfinables = lib.mkEnableOption '' killing of processes which have an AppArmor profile enabled (in [](#opt-security.apparmor.policies)) but are not confined (because AppArmor can only confine new processes). @@ -92,7 +89,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { assertions = map (policy: { assertion = match ".*/.*" policy == null; message = "`security.apparmor.policies.\"${policy}\"' must not contain a slash."; @@ -108,15 +105,15 @@ in environment.etc."apparmor.d".source = pkgs.linkFarm "apparmor.d" ( # It's important to put only enabledPolicies here and not all cfg.policies # because aa-remove-unknown reads profiles from all /etc/apparmor.d/* - mapAttrsToList (name: p: { inherit name; path = p.profile; }) enabledPolicies ++ - mapAttrsToList (name: path: { inherit name path; }) cfg.includes + lib.mapAttrsToList (name: p: { inherit name; path = p.profile; }) enabledPolicies ++ + lib.mapAttrsToList (name: path: { inherit name path; }) cfg.includes ); environment.etc."apparmor/parser.conf".text = '' ${if cfg.enableCache then "write-cache" else "skip-cache"} cache-loc /var/cache/apparmor Include /etc/apparmor.d '' + - concatMapStrings (p: "Include ${p}/etc/apparmor.d\n") cfg.packages; + lib.concatMapStrings (p: "Include ${p}/etc/apparmor.d\n") cfg.packages; # For aa-logprof environment.etc."apparmor/apparmor.conf".text = '' ''; @@ -142,7 +139,7 @@ in # 3 - force all perms on the rule to be user default_owner_prompt = 1 - custom_includes = /etc/apparmor.d ${concatMapStringsSep " " (p: "${p}/etc/apparmor.d") cfg.packages} + custom_includes = /etc/apparmor.d ${lib.concatMapStringsSep " " (p: "${p}/etc/apparmor.d") cfg.packages} [qualifiers] ${pkgs.runtimeShell} = icnu @@ -187,17 +184,17 @@ in xargs --verbose --no-run-if-empty --delimiter='\n' \ kill ''; - commonOpts = p: "--verbose --show-cache ${optionalString (!p.enforce) "--complain "}${p.profile}"; + commonOpts = p: "--verbose --show-cache ${lib.optionalString (!p.enforce) "--complain "}${p.profile}"; in { Type = "oneshot"; RemainAfterExit = "yes"; ExecStartPre = "${pkgs.apparmor-utils}/bin/aa-teardown"; - ExecStart = mapAttrsToList (n: p: "${pkgs.apparmor-parser}/bin/apparmor_parser --add ${commonOpts p}") enabledPolicies; - ExecStartPost = optional cfg.killUnconfinedConfinables killUnconfinedConfinables; + ExecStart = lib.mapAttrsToList (n: p: "${pkgs.apparmor-parser}/bin/apparmor_parser --add ${commonOpts p}") enabledPolicies; + ExecStartPost = lib.optional cfg.killUnconfinedConfinables killUnconfinedConfinables; ExecReload = # Add or replace into the kernel profiles in enabledPolicies # (because AppArmor can do that without stopping the processes already confined). - mapAttrsToList (n: p: "${pkgs.apparmor-parser}/bin/apparmor_parser --replace ${commonOpts p}") enabledPolicies ++ + lib.mapAttrsToList (n: p: "${pkgs.apparmor-parser}/bin/apparmor_parser --replace ${commonOpts p}") enabledPolicies ++ # Remove from the kernel any profile whose name is not # one of the names within the content of the profiles in enabledPolicies # (indirectly read from /etc/apparmor.d/*, without recursing into sub-directory). @@ -205,7 +202,7 @@ in [ "${pkgs.apparmor-utils}/bin/aa-remove-unknown" ] ++ # Optionally kill the processes which are unconfined but now have a profile loaded # (because AppArmor can only start to confine new processes). - optional cfg.killUnconfinedConfinables killUnconfinedConfinables; + lib.optional cfg.killUnconfinedConfinables killUnconfinedConfinables; ExecStop = "${pkgs.apparmor-utils}/bin/aa-teardown"; CacheDirectory = [ "apparmor" "apparmor/logprof" ]; CacheDirectoryMode = "0700"; @@ -213,5 +210,5 @@ in }; }; - meta.maintainers = with maintainers; [ julm ]; + meta.maintainers = with lib.maintainers; [ julm ]; } From a62e66394b7bde3dd5f9c2e5c4535aea7708dd61 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:32 +0200 Subject: [PATCH 037/166] nixos/security.audit: remove `with lib;` --- nixos/modules/security/audit.nix | 25 +++++++++++-------------- 1 file changed, 11 insertions(+), 14 deletions(-) diff --git a/nixos/modules/security/audit.nix b/nixos/modules/security/audit.nix index 403aeff020dc..f7dde61f8d4b 100644 --- a/nixos/modules/security/audit.nix +++ b/nixos/modules/security/audit.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.security.audit; enabled = cfg.enable == "lock" || cfg.enable; @@ -29,7 +26,7 @@ let # Put the rules in a temporary file owned and only readable by root rulesfile="$(mktemp)" - ${concatMapStrings (x: "echo '${x}' >> $rulesfile\n") cfg.rules} + ${lib.concatMapStrings (x: "echo '${x}' >> $rulesfile\n") cfg.rules} # Apply the requested rules auditctl -R "$rulesfile" @@ -53,8 +50,8 @@ let in { options = { security.audit = { - enable = mkOption { - type = types.enum [ false true "lock" ]; + enable = lib.mkOption { + type = lib.types.enum [ false true "lock" ]; default = false; description = '' Whether to enable the Linux audit system. The special `lock` value can be used to @@ -64,14 +61,14 @@ in { ''; }; - failureMode = mkOption { - type = types.enum [ "silent" "printk" "panic" ]; + failureMode = lib.mkOption { + type = lib.types.enum [ "silent" "printk" "panic" ]; default = "printk"; description = "How to handle critical errors in the auditing system"; }; - backlogLimit = mkOption { - type = types.int; + backlogLimit = lib.mkOption { + type = lib.types.int; default = 64; # Apparently the kernel default description = '' The maximum number of outstanding audit buffers allowed; exceeding this is @@ -79,8 +76,8 @@ in { ''; }; - rateLimit = mkOption { - type = types.int; + rateLimit = lib.mkOption { + type = lib.types.int; default = 0; description = '' The maximum messages per second permitted before triggering a failure as @@ -88,8 +85,8 @@ in { ''; }; - rules = mkOption { - type = types.listOf types.str; # (types.either types.str (types.submodule rule)); + rules = lib.mkOption { + type = lib.types.listOf lib.types.str; # (types.either types.str (types.submodule rule)); default = []; example = [ "-a exit,always -F arch=b64 -S execve" ]; description = '' From 3c80b14a814541e27632d7676d3530236c6acdf8 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:32 +0200 Subject: [PATCH 038/166] nixos/security.please: remove `with lib;` --- nixos/modules/security/please.nix | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-) diff --git a/nixos/modules/security/please.nix b/nixos/modules/security/please.nix index 39df5dfd50d5..05a189dfbaaa 100644 --- a/nixos/modules/security/please.nix +++ b/nixos/modules/security/please.nix @@ -1,22 +1,19 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.security.please; ini = pkgs.formats.ini { }; in { options.security.please = { - enable = mkEnableOption '' + enable = lib.mkEnableOption '' please, a Sudo clone which allows a users to execute a command or edit a file as another user ''; - package = mkPackageOption pkgs "please" { }; + package = lib.mkPackageOption pkgs "please" { }; - wheelNeedsPassword = mkOption { - type = types.bool; + wheelNeedsPassword = lib.mkOption { + type = lib.types.bool; default = true; description = '' Whether users of the `wheel` group must provide a password to run @@ -25,7 +22,7 @@ in ''; }; - settings = mkOption { + settings = lib.mkOption { type = ini.type; default = { }; example = { @@ -53,7 +50,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { security.wrappers = let owner = "root"; @@ -110,6 +107,6 @@ in usshAuth = true; }; - meta.maintainers = with maintainers; [ azahi ]; + meta.maintainers = with lib.maintainers; [ azahi ]; }; } From 503fd3014a4719adc16fe6709304e330eb276b7b Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:33 +0200 Subject: [PATCH 039/166] nixos/services.oxidized: remove `with lib;` --- nixos/modules/services/admin/oxidized.nix | 31 ++++++++++------------- 1 file changed, 14 insertions(+), 17 deletions(-) diff --git a/nixos/modules/services/admin/oxidized.nix b/nixos/modules/services/admin/oxidized.nix index 49ea3ced76a4..e20994067448 100644 --- a/nixos/modules/services/admin/oxidized.nix +++ b/nixos/modules/services/admin/oxidized.nix @@ -1,39 +1,36 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.services.oxidized; in { options.services.oxidized = { - enable = mkEnableOption "the oxidized configuration backup service"; + enable = lib.mkEnableOption "the oxidized configuration backup service"; - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; default = "oxidized"; description = '' User under which the oxidized service runs. ''; }; - group = mkOption { - type = types.str; + group = lib.mkOption { + type = lib.types.str; default = "oxidized"; description = '' Group under which the oxidized service runs. ''; }; - dataDir = mkOption { - type = types.path; + dataDir = lib.mkOption { + type = lib.types.path; default = "/var/lib/oxidized"; description = "State directory for the oxidized service."; }; - configFile = mkOption { - type = types.path; - example = literalExpression '' + configFile = lib.mkOption { + type = lib.types.path; + example = lib.literalExpression '' pkgs.writeText "oxidized-config.yml" ''' --- debug: true @@ -67,9 +64,9 @@ in ''; }; - routerDB = mkOption { - type = types.path; - example = literalExpression '' + routerDB = lib.mkOption { + type = lib.types.path; + example = lib.literalExpression '' pkgs.writeText "oxidized-router.db" ''' hostname-sw1:powerconnect:username1:password2 hostname-sw2:procurve:username2:password2 @@ -82,7 +79,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { users.groups.${cfg.group} = { }; users.users.${cfg.user} = { description = "Oxidized service user"; From 5a670b332ab7653961d363a5ea6cfefe525398b7 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:33 +0200 Subject: [PATCH 040/166] nixos/services.salt.minion: remove `with lib;` --- nixos/modules/services/admin/salt/minion.nix | 11 ++++------- 1 file changed, 4 insertions(+), 7 deletions(-) diff --git a/nixos/modules/services/admin/salt/minion.nix b/nixos/modules/services/admin/salt/minion.nix index 5d4efc6541c7..fde51a06769a 100644 --- a/nixos/modules/services/admin/salt/minion.nix +++ b/nixos/modules/services/admin/salt/minion.nix @@ -1,7 +1,4 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.services.salt.minion; @@ -21,9 +18,9 @@ in { options = { services.salt.minion = { - enable = mkEnableOption "Salt configuration management system minion service"; - configuration = mkOption { - type = types.attrs; + enable = lib.mkEnableOption "Salt configuration management system minion service"; + configuration = lib.mkOption { + type = lib.types.attrs; default = {}; description = '' Salt minion configuration as Nix attribute set. @@ -34,7 +31,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment = { # Set this up in /etc/salt/minion so `salt-call`, etc. work. # The alternatives are From 82146f6a7105cc865f1730fc2c9d46d8f03bdf55 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:33 +0200 Subject: [PATCH 041/166] nixos/services.activemq: remove `with lib;` --- .../services/amqp/activemq/default.nix | 50 +++++++++---------- 1 file changed, 23 insertions(+), 27 deletions(-) diff --git a/nixos/modules/services/amqp/activemq/default.nix b/nixos/modules/services/amqp/activemq/default.nix index 5c886161e44c..53814d71a5ac 100644 --- a/nixos/modules/services/amqp/activemq/default.nix +++ b/nixos/modules/services/amqp/activemq/default.nix @@ -1,18 +1,14 @@ { config, lib, pkgs, ... }: - -with pkgs; -with lib; - let cfg = config.services.activemq; - activemqBroker = runCommand "activemq-broker" + activemqBroker = pkgs.runCommand "activemq-broker" { - nativeBuildInputs = [ jdk ]; + nativeBuildInputs = [ pkgs.jdk ]; } '' mkdir -p $out/lib - source ${activemq}/lib/classpath.env + source ${pkgs.activemq}/lib/classpath.env export CLASSPATH ln -s "${./ActiveMQBroker.java}" ActiveMQBroker.java javac -d $out/lib ActiveMQBroker.java @@ -23,25 +19,25 @@ in options = { services.activemq = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = '' Enable the Apache ActiveMQ message broker service. ''; }; - configurationDir = mkOption { - default = "${activemq}/conf"; - defaultText = literalExpression ''"''${pkgs.activemq}/conf"''; - type = types.str; + configurationDir = lib.mkOption { + default = "${pkgs.activemq}/conf"; + defaultText = lib.literalExpression ''"''${pkgs.activemq}/conf"''; + type = lib.types.str; description = '' The base directory for ActiveMQ's configuration. By default, this directory is searched for a file named activemq.xml, which should contain the configuration for the broker service. ''; }; - configurationURI = mkOption { - type = types.str; + configurationURI = lib.mkOption { + type = lib.types.str; default = "xbean:activemq.xml"; description = '' The URI that is passed along to the BrokerFactory to @@ -51,8 +47,8 @@ in an activemq.xml configuration file in it. ''; }; - baseDir = mkOption { - type = types.str; + baseDir = lib.mkOption { + type = lib.types.str; default = "/var/activemq"; description = '' The base directory where ActiveMQ stores its persistent data and logs. @@ -61,10 +57,10 @@ in this in activemq.xml. ''; }; - javaProperties = mkOption { - type = types.attrs; + javaProperties = lib.mkOption { + type = lib.types.attrs; default = { }; - example = literalExpression '' + example = lib.literalExpression '' { "java.net.preferIPv4Stack" = "true"; } @@ -73,7 +69,7 @@ in "activemq.base" = "${cfg.baseDir}"; "activemq.data" = "${cfg.baseDir}/data"; "activemq.conf" = "${cfg.configurationDir}"; - "activemq.home" = "${activemq}"; + "activemq.home" = "${pkgs.activemq}"; } // attrs; description = '' Specifies Java properties that are sent to the ActiveMQ @@ -83,8 +79,8 @@ in given reasonable defaults. ''; }; - extraJavaOptions = mkOption { - type = types.separatedString " "; + extraJavaOptions = lib.mkOption { + type = lib.types.separatedString " "; default = ""; example = "-Xmx2G -Xms2G -XX:MaxPermSize=512M"; description = '' @@ -95,7 +91,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { users.users.activemq = { description = "ActiveMQ server user"; group = "activemq"; @@ -118,13 +114,13 @@ in systemd.services.activemq = { wantedBy = [ "multi-user.target" ]; after = [ "network.target" ]; - path = [ jre ]; + path = [ pkgs.jre ]; serviceConfig.User = "activemq"; script = '' - source ${activemq}/lib/classpath.env + source ${pkgs.activemq}/lib/classpath.env export CLASSPATH=${activemqBroker}/lib:${cfg.configurationDir}:$CLASSPATH exec java \ - ${concatStringsSep " \\\n" (mapAttrsToList (name: value: "-D${name}=${value}") cfg.javaProperties)} \ + ${lib.concatStringsSep " \\\n" (lib.mapAttrsToList (name: value: "-D${name}=${value}") cfg.javaProperties)} \ ${cfg.extraJavaOptions} ActiveMQBroker "${cfg.configurationURI}" ''; }; From c62a55f1b60b082a45b9bf3175d621e7d04f9941 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:34 +0200 Subject: [PATCH 042/166] nixos/services.botamusique: remove `with lib;` --- nixos/modules/services/audio/botamusique.nix | 21 +++++++++----------- 1 file changed, 9 insertions(+), 12 deletions(-) diff --git a/nixos/modules/services/audio/botamusique.nix b/nixos/modules/services/audio/botamusique.nix index c764a79b1166..88ab232efae5 100644 --- a/nixos/modules/services/audio/botamusique.nix +++ b/nixos/modules/services/audio/botamusique.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.botamusique; @@ -12,34 +9,34 @@ in meta.maintainers = with lib.maintainers; [ hexa ]; options.services.botamusique = { - enable = mkEnableOption "botamusique, a bot to play audio streams on mumble"; + enable = lib.mkEnableOption "botamusique, a bot to play audio streams on mumble"; - package = mkPackageOption pkgs "botamusique" { }; + package = lib.mkPackageOption pkgs "botamusique" { }; - settings = mkOption { - type = with types; submodule { + settings = lib.mkOption { + type = with lib.types; submodule { freeformType = format.type; options = { - server.host = mkOption { + server.host = lib.mkOption { type = types.str; default = "localhost"; example = "mumble.example.com"; description = "Hostname of the mumble server to connect to."; }; - server.port = mkOption { + server.port = lib.mkOption { type = types.port; default = 64738; description = "Port of the mumble server to connect to."; }; - bot.username = mkOption { + bot.username = lib.mkOption { type = types.str; default = "botamusique"; description = "Name the bot should appear with."; }; - bot.comment = mkOption { + bot.comment = lib.mkOption { type = types.str; default = "Hi, I'm here to play radio, local music or youtube/soundcloud music. Have fun!"; description = "Comment displayed for the bot."; @@ -54,7 +51,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.botamusique = { after = [ "network.target" ]; wantedBy = [ "multi-user.target" ]; From cab8ab375c5bc9c30b4ea3c8c18f5355cd0a5913 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:34 +0200 Subject: [PATCH 043/166] nixos/services.gmediarender: remove `with lib;` --- nixos/modules/services/audio/gmediarender.nix | 45 +++++++++---------- 1 file changed, 21 insertions(+), 24 deletions(-) diff --git a/nixos/modules/services/audio/gmediarender.nix b/nixos/modules/services/audio/gmediarender.nix index 3f031aeedb7b..ee16400d48d4 100644 --- a/nixos/modules/services/audio/gmediarender.nix +++ b/nixos/modules/services/audio/gmediarender.nix @@ -1,58 +1,55 @@ { pkgs, lib, config, utils, ... }: - -with lib; - let cfg = config.services.gmediarender; in { options.services.gmediarender = { - enable = mkEnableOption "the gmediarender DLNA renderer"; + enable = lib.mkEnableOption "the gmediarender DLNA renderer"; - audioDevice = mkOption { - type = types.nullOr types.str; + audioDevice = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; description = '' The audio device to use. ''; }; - audioSink = mkOption { - type = types.nullOr types.str; + audioSink = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; description = '' The audio sink to use. ''; }; - friendlyName = mkOption { - type = types.nullOr types.str; + friendlyName = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; description = '' A "friendly name" for identifying the endpoint. ''; }; - initialVolume = mkOption { - type = types.nullOr types.int; + initialVolume = lib.mkOption { + type = lib.types.nullOr lib.types.int; default = 0; description = '' A default volume attenuation (in dB) for the endpoint. ''; }; - package = mkPackageOption pkgs "gmediarender" { + package = lib.mkPackageOption pkgs "gmediarender" { default = "gmrender-resurrect"; }; - port = mkOption { - type = types.nullOr types.port; + port = lib.mkOption { + type = lib.types.nullOr lib.types.port; default = null; description = "Port that will be used to accept client connections."; }; - uuid = mkOption { - type = types.nullOr types.str; + uuid = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; description = '' A UUID for uniquely identifying the endpoint. If you have @@ -61,7 +58,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd = { services.gmediarender = { wants = [ "network-online.target" ]; @@ -78,12 +75,12 @@ in SupplementaryGroups = [ "audio" ]; ExecStart = "${cfg.package}/bin/gmediarender " + - optionalString (cfg.audioDevice != null) ("--gstout-audiodevice=${utils.escapeSystemdExecArg cfg.audioDevice} ") + - optionalString (cfg.audioSink != null) ("--gstout-audiosink=${utils.escapeSystemdExecArg cfg.audioSink} ") + - optionalString (cfg.friendlyName != null) ("--friendly-name=${utils.escapeSystemdExecArg cfg.friendlyName} ") + - optionalString (cfg.initialVolume != 0) ("--initial-volume=${toString cfg.initialVolume} ") + - optionalString (cfg.port != null) ("--port=${toString cfg.port} ") + - optionalString (cfg.uuid != null) ("--uuid=${utils.escapeSystemdExecArg cfg.uuid} "); + lib.optionalString (cfg.audioDevice != null) ("--gstout-audiodevice=${utils.escapeSystemdExecArg cfg.audioDevice} ") + + lib.optionalString (cfg.audioSink != null) ("--gstout-audiosink=${utils.escapeSystemdExecArg cfg.audioSink} ") + + lib.optionalString (cfg.friendlyName != null) ("--friendly-name=${utils.escapeSystemdExecArg cfg.friendlyName} ") + + lib.optionalString (cfg.initialVolume != 0) ("--initial-volume=${toString cfg.initialVolume} ") + + lib.optionalString (cfg.port != null) ("--port=${toString cfg.port} ") + + lib.optionalString (cfg.uuid != null) ("--uuid=${utils.escapeSystemdExecArg cfg.uuid} "); Restart = "always"; RuntimeDirectory = "gmediarender"; From 496d11787dd7c89a5c35ea010d262908b249a340 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:34 +0200 Subject: [PATCH 044/166] nixos/services.gonic: remove `with lib;` --- nixos/modules/services/audio/gonic.nix | 15 ++++++--------- 1 file changed, 6 insertions(+), 9 deletions(-) diff --git a/nixos/modules/services/audio/gonic.nix b/nixos/modules/services/audio/gonic.nix index 15a35571acba..5f55f776bf8b 100644 --- a/nixos/modules/services/audio/gonic.nix +++ b/nixos/modules/services/audio/gonic.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.gonic; settingsFormat = pkgs.formats.keyValue { @@ -13,11 +10,11 @@ in options = { services.gonic = { - enable = mkEnableOption "Gonic music server"; + enable = lib.mkEnableOption "Gonic music server"; - settings = mkOption rec { + settings = lib.mkOption rec { type = settingsFormat.type; - apply = recursiveUpdate default; + apply = lib.recursiveUpdate default; default = { listen-addr = "127.0.0.1:4747"; cache-path = "/var/cache/gonic"; @@ -36,7 +33,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.gonic = { description = "Gonic Media Server"; after = [ "network.target" ]; @@ -45,7 +42,7 @@ in ExecStart = let # these values are null by default but should not appear in the final config - filteredSettings = filterAttrs (n: v: !((n == "tls-cert" || n == "tls-key") && v == null)) cfg.settings; + filteredSettings = lib.filterAttrs (n: v: !((n == "tls-cert" || n == "tls-key") && v == null)) cfg.settings; in "${pkgs.gonic}/bin/gonic -config-path ${settingsFormat.generate "gonic" filteredSettings}"; DynamicUser = true; @@ -89,5 +86,5 @@ in }; }; - meta.maintainers = [ maintainers.autrimpo ]; + meta.maintainers = [ lib.maintainers.autrimpo ]; } From dfd031a486d37a801105c62dbb5e0eecd0b0f9b6 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:34 +0200 Subject: [PATCH 045/166] nixos/services.goxlr-utility: remove `with lib;` --- .../modules/services/audio/goxlr-utility.nix | 21 ++++++++----------- 1 file changed, 9 insertions(+), 12 deletions(-) diff --git a/nixos/modules/services/audio/goxlr-utility.nix b/nixos/modules/services/audio/goxlr-utility.nix index 00aaa77a24d5..bd8f285d6739 100644 --- a/nixos/modules/services/audio/goxlr-utility.nix +++ b/nixos/modules/services/audio/goxlr-utility.nix @@ -1,25 +1,22 @@ { config, lib, pkgs, ... }: - let cfg = config.services.goxlr-utility; in - -with lib; { options = { services.goxlr-utility = { - enable = mkOption { + enable = lib.mkOption { default = false; - type = types.bool; + type = lib.types.bool; description = '' Whether to enable goxlr-utility for controlling your TC-Helicon GoXLR or GoXLR Mini ''; }; - package = mkPackageOption pkgs "goxlr-utility" { }; - autoStart.xdg = mkOption { + package = lib.mkPackageOption pkgs "goxlr-utility" { }; + autoStart.xdg = lib.mkOption { default = true; - type = with types; bool; + type = with lib.types; bool; description = '' Start the daemon automatically using XDG autostart. Sets `xdg.autostart.enable = true` if not already enabled. @@ -44,16 +41,16 @@ with lib; ''; }; in - mkIf config.services.goxlr-utility.enable { + lib.mkIf config.services.goxlr-utility.enable { services.udev.packages = [ cfg.package ]; - xdg.autostart.enable = mkIf cfg.autoStart.xdg true; - environment.systemPackages = mkIf cfg.autoStart.xdg + xdg.autostart.enable = lib.mkIf cfg.autoStart.xdg true; + environment.systemPackages = lib.mkIf cfg.autoStart.xdg [ cfg.package goxlr-autostart ]; }; - meta.maintainers = with maintainers; [ errnoh ]; + meta.maintainers = with lib.maintainers; [ errnoh ]; } From 1d19c390cf02e80b81466d860a1fe2b871667d94 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:35 +0200 Subject: [PATCH 046/166] nixos/services.hqplayerd: remove `with lib;` --- nixos/modules/services/audio/hqplayerd.nix | 37 ++++++++++------------ 1 file changed, 17 insertions(+), 20 deletions(-) diff --git a/nixos/modules/services/audio/hqplayerd.nix b/nixos/modules/services/audio/hqplayerd.nix index d6ac8c58c03a..85e633b64457 100644 --- a/nixos/modules/services/audio/hqplayerd.nix +++ b/nixos/modules/services/audio/hqplayerd.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.hqplayerd; pkg = pkgs.hqplayerd; @@ -12,11 +9,11 @@ in { options = { services.hqplayerd = { - enable = mkEnableOption "HQPlayer Embedded"; + enable = lib.mkEnableOption "HQPlayer Embedded"; auth = { - username = mkOption { - type = types.nullOr types.str; + username = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; description = '' Username used for HQPlayer's WebUI. @@ -26,8 +23,8 @@ in ''; }; - password = mkOption { - type = types.nullOr types.str; + password = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; description = '' Password used for HQPlayer's WebUI. @@ -38,8 +35,8 @@ in }; }; - licenseFile = mkOption { - type = types.nullOr types.path; + licenseFile = lib.mkOption { + type = lib.types.nullOr lib.types.path; default = null; description = '' Path to the HQPlayer license key file. @@ -49,16 +46,16 @@ in ''; }; - openFirewall = mkOption { - type = types.bool; + openFirewall = lib.mkOption { + type = lib.types.bool; default = false; description = '' Opens ports needed for the WebUI and controller API. ''; }; - config = mkOption { - type = types.nullOr types.lines; + config = lib.mkOption { + type = lib.types.nullOr lib.types.lines; default = null; description = '' HQplayer daemon configuration, written to /etc/hqplayer/hqplayerd.xml. @@ -69,7 +66,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { assertions = [ { assertion = (cfg.auth.username != null -> cfg.auth.password != null) @@ -80,13 +77,13 @@ in environment = { etc = { - "hqplayer/hqplayerd.xml" = mkIf (cfg.config != null) { source = pkgs.writeText "hqplayerd.xml" cfg.config; }; - "hqplayer/hqplayerd4-key.xml" = mkIf (cfg.licenseFile != null) { source = cfg.licenseFile; }; + "hqplayer/hqplayerd.xml" = lib.mkIf (cfg.config != null) { source = pkgs.writeText "hqplayerd.xml" cfg.config; }; + "hqplayer/hqplayerd4-key.xml" = lib.mkIf (cfg.licenseFile != null) { source = cfg.licenseFile; }; }; systemPackages = [ pkg ]; }; - networking.firewall = mkIf cfg.openFirewall { + networking.firewall = lib.mkIf cfg.openFirewall { allowedTCPPorts = [ 8088 4321 ]; }; @@ -107,7 +104,7 @@ in unitConfig.ConditionPathExists = [ configDir stateDir ]; - restartTriggers = optionals (cfg.config != null) [ config.environment.etc."hqplayer/hqplayerd.xml".source ]; + restartTriggers = lib.optionals (cfg.config != null) [ config.environment.etc."hqplayer/hqplayerd.xml".source ]; preStart = '' cp -r "${pkg}/var/lib/hqplayer/web" "${stateDir}" @@ -117,7 +114,7 @@ in echo "creating initial config file" install -m 0644 "${pkg}/etc/hqplayer/hqplayerd.xml" "${configDir}/hqplayerd.xml" fi - '' + optionalString (cfg.auth.username != null && cfg.auth.password != null) '' + '' + lib.optionalString (cfg.auth.username != null && cfg.auth.password != null) '' ${pkg}/bin/hqplayerd -s ${cfg.auth.username} ${cfg.auth.password} ''; }; From e8fa5a92e93ef7396d8aa85d41331664eda2343c Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:35 +0200 Subject: [PATCH 047/166] nixos/services.icecast: remove `with lib;` --- nixos/modules/services/audio/icecast.nix | 45 +++++++++++------------- 1 file changed, 21 insertions(+), 24 deletions(-) diff --git a/nixos/modules/services/audio/icecast.nix b/nixos/modules/services/audio/icecast.nix index 9237baa007da..820674c4341d 100644 --- a/nixos/modules/services/audio/icecast.nix +++ b/nixos/modules/services/audio/icecast.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.icecast; configFile = pkgs.writeText "icecast.xml" '' @@ -44,62 +41,62 @@ in { services.icecast = { - enable = mkEnableOption "Icecast server"; + enable = lib.mkEnableOption "Icecast server"; - hostname = mkOption { - type = types.nullOr types.str; + hostname = lib.mkOption { + type = lib.types.nullOr lib.types.str; description = "DNS name or IP address that will be used for the stream directory lookups or possibly the playlist generation if a Host header is not provided."; default = config.networking.domain; - defaultText = literalExpression "config.networking.domain"; + defaultText = lib.literalExpression "config.networking.domain"; }; admin = { - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; description = "Username used for all administration functions."; default = "admin"; }; - password = mkOption { - type = types.str; + password = lib.mkOption { + type = lib.types.str; description = "Password used for all administration functions."; }; }; - logDir = mkOption { - type = types.path; + logDir = lib.mkOption { + type = lib.types.path; description = "Base directory used for logging."; default = "/var/log/icecast"; }; listen = { - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; description = "TCP port that will be used to accept client connections."; default = 8000; }; - address = mkOption { - type = types.str; + address = lib.mkOption { + type = lib.types.str; description = "Address Icecast will listen on."; default = "::"; }; }; - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; description = "User privileges for the server."; default = "nobody"; }; - group = mkOption { - type = types.str; + group = lib.mkOption { + type = lib.types.str; description = "Group privileges for the server."; default = "nogroup"; }; - extraConf = mkOption { - type = types.lines; + extraConf = lib.mkOption { + type = lib.types.lines; description = "icecast.xml content."; default = ""; }; @@ -111,7 +108,7 @@ in { ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.icecast = { after = [ "network.target" ]; From 291d92e5290ee4138cc574e8ded58aa87b216bc9 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:35 +0200 Subject: [PATCH 048/166] nixos/services.jack: remove `with lib;` --- nixos/modules/services/audio/jack.nix | 59 +++++++++++++-------------- 1 file changed, 28 insertions(+), 31 deletions(-) diff --git a/nixos/modules/services/audio/jack.nix b/nixos/modules/services/audio/jack.nix index 767f1add1cae..c71b8ff13fa6 100644 --- a/nixos/modules/services/audio/jack.nix +++ b/nixos/modules/services/audio/jack.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.jack; @@ -10,29 +7,29 @@ let enable32BitAlsaPlugins = cfg.alsa.support32Bit && pkgs.stdenv.hostPlatform.isx86_64 && pkgs.pkgsi686Linux.alsa-lib != null; - umaskNeeded = versionOlder cfg.jackd.package.version "1.9.12"; - bridgeNeeded = versionAtLeast cfg.jackd.package.version "1.9.12"; + umaskNeeded = lib.versionOlder cfg.jackd.package.version "1.9.12"; + bridgeNeeded = lib.versionAtLeast cfg.jackd.package.version "1.9.12"; in { options = { services.jack = { jackd = { - enable = mkEnableOption '' + enable = lib.mkEnableOption '' JACK Audio Connection Kit. You need to add yourself to the "jackaudio" group ''; - package = mkPackageOption pkgs "jack2" { + package = lib.mkPackageOption pkgs "jack2" { example = "jack1"; } // { # until jack1 promiscuous mode is fixed internal = true; }; - extraOptions = mkOption { - type = types.listOf types.str; + extraOptions = lib.mkOption { + type = lib.types.listOf lib.types.str; default = [ "-dalsa" ]; - example = literalExpression '' + example = lib.literalExpression '' [ "-dalsa" "--device" "hw:1" ]; ''; description = '' @@ -40,8 +37,8 @@ in { ''; }; - session = mkOption { - type = types.lines; + session = lib.mkOption { + type = lib.types.lines; description = '' Commands to run after JACK is started. ''; @@ -50,16 +47,16 @@ in { }; alsa = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = true; description = '' Route audio to/from generic ALSA-using applications using ALSA JACK PCM plugin. ''; }; - support32Bit = mkOption { - type = types.bool; + support32Bit = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether to support sound for 32-bit ALSA applications on 64-bit system. @@ -68,8 +65,8 @@ in { }; loopback = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = '' Create ALSA loopback device, instead of using PCM plugin. Has broader @@ -78,23 +75,23 @@ in { ''; }; - index = mkOption { - type = types.int; + index = lib.mkOption { + type = lib.types.int; default = 10; description = '' Index of an ALSA loopback device. ''; }; - config = mkOption { - type = types.lines; + config = lib.mkOption { + type = lib.types.lines; description = '' ALSA config for loopback device. ''; }; - dmixConfig = mkOption { - type = types.lines; + dmixConfig = lib.mkOption { + type = lib.types.lines; default = ""; example = '' period_size 2048 @@ -107,8 +104,8 @@ in { ''; }; - session = mkOption { - type = types.lines; + session = lib.mkOption { + type = lib.types.lines; description = '' Additional commands to run to setup loopback device. ''; @@ -119,9 +116,9 @@ in { }; - config = mkMerge [ + config = lib.mkMerge [ - (mkIf pcmPlugin { + (lib.mkIf pcmPlugin { environment.etc."alsa/conf.d/98-jack.conf".text = '' pcm_type.jack { libs.native = ${pkgs.alsa-plugins}/lib/alsa-lib/libasound_module_pcm_jack.so ; @@ -136,13 +133,13 @@ in { ''; }) - (mkIf loopback { + (lib.mkIf loopback { boot.kernelModules = [ "snd-aloop" ]; boot.kernelParams = [ "snd-aloop.index=${toString cfg.loopback.index}" ]; environment.etc."alsa/conf.d/99-jack-loopback.conf".text = cfg.loopback.config; }) - (mkIf cfg.jackd.enable { + (lib.mkIf cfg.jackd.enable { services.jack.jackd.session = '' ${lib.optionalString bridgeNeeded "${pkgs.a2jmidid}/bin/a2jmidid -e &"} ''; @@ -247,7 +244,7 @@ in { ExecStart = "${cfg.jackd.package}/bin/jackd ${lib.escapeShellArgs cfg.jackd.extraOptions}"; LimitRTPRIO = 99; LimitMEMLOCK = "infinity"; - } // optionalAttrs umaskNeeded { + } // lib.optionalAttrs umaskNeeded { UMask = "007"; }; path = [ cfg.jackd.package ]; From f645147c7e166f58dae22a49d3333f32aa32e1b7 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:36 +0200 Subject: [PATCH 049/166] nixos/services.jmusicbot: remove `with lib;` --- nixos/modules/services/audio/jmusicbot.nix | 16 +++++++--------- 1 file changed, 7 insertions(+), 9 deletions(-) diff --git a/nixos/modules/services/audio/jmusicbot.nix b/nixos/modules/services/audio/jmusicbot.nix index d1317facf273..6cd348e68e45 100644 --- a/nixos/modules/services/audio/jmusicbot.nix +++ b/nixos/modules/services/audio/jmusicbot.nix @@ -1,18 +1,16 @@ { config, lib, pkgs, ... }: - -with lib; let cfg = config.services.jmusicbot; in { options = { services.jmusicbot = { - enable = mkEnableOption "jmusicbot, a Discord music bot that's easy to set up and run yourself"; + enable = lib.mkEnableOption "jmusicbot, a Discord music bot that's easy to set up and run yourself"; - package = mkPackageOption pkgs "jmusicbot" { }; + package = lib.mkPackageOption pkgs "jmusicbot" { }; - stateDir = mkOption { - type = types.path; + stateDir = lib.mkOption { + type = lib.types.path; description = '' The directory where config.txt and serversettings.json is saved. If left as the default value this directory will automatically be created before JMusicBot starts, otherwise the sysadmin is responsible for ensuring the directory exists with appropriate ownership and permissions. @@ -23,20 +21,20 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.jmusicbot = { wantedBy = [ "multi-user.target" ]; wants = [ "network-online.target" ]; after = [ "network-online.target" ]; description = "Discord music bot that's easy to set up and run yourself!"; - serviceConfig = mkMerge [{ + serviceConfig = lib.mkMerge [{ ExecStart = "${cfg.package}/bin/JMusicBot"; WorkingDirectory = cfg.stateDir; Restart = "always"; RestartSec = 20; DynamicUser = true; } - (mkIf (cfg.stateDir == "/var/lib/jmusicbot") { StateDirectory = "jmusicbot"; })]; + (lib.mkIf (cfg.stateDir == "/var/lib/jmusicbot") { StateDirectory = "jmusicbot"; })]; }; }; From de5c62db29d39f7d24e6ecd79f7bd16288e55844 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:36 +0200 Subject: [PATCH 050/166] nixos/services.liquidsoap: remove `with lib;` --- nixos/modules/services/audio/liquidsoap.nix | 11 ++++------- 1 file changed, 4 insertions(+), 7 deletions(-) diff --git a/nixos/modules/services/audio/liquidsoap.nix b/nixos/modules/services/audio/liquidsoap.nix index bd35e01b60d6..ece282f0568f 100644 --- a/nixos/modules/services/audio/liquidsoap.nix +++ b/nixos/modules/services/audio/liquidsoap.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let streams = builtins.attrNames config.services.liquidsoap.streams; @@ -29,7 +26,7 @@ in options = { - services.liquidsoap.streams = mkOption { + services.liquidsoap.streams = lib.mkOption { description = '' Set of Liquidsoap streams to start, @@ -38,7 +35,7 @@ in default = {}; - example = literalExpression '' + example = lib.literalExpression '' { myStream1 = "/etc/liquidsoap/myStream1.liq"; myStream2 = ./myStream2.liq; @@ -46,13 +43,13 @@ in } ''; - type = types.attrsOf (types.either types.path types.str); + type = lib.types.attrsOf (lib.types.either lib.types.path lib.types.str); }; }; ##### implementation - config = mkIf (builtins.length streams != 0) { + config = lib.mkIf (builtins.length streams != 0) { users.users.liquidsoap = { uid = config.ids.uids.liquidsoap; From b477479cb7b1f89edc0bf02872eea81afe37b4ff Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:37 +0200 Subject: [PATCH 051/166] nixos/services.mpdscribble: remove `with lib;` --- nixos/modules/services/audio/mpdscribble.nix | 71 ++++++++++---------- 1 file changed, 34 insertions(+), 37 deletions(-) diff --git a/nixos/modules/services/audio/mpdscribble.nix b/nixos/modules/services/audio/mpdscribble.nix index 3c7270a3a4a4..9e1f2c50a924 100644 --- a/nixos/modules/services/audio/mpdscribble.nix +++ b/nixos/modules/services/audio/mpdscribble.nix @@ -1,7 +1,4 @@ { config, lib, options, pkgs, ... }: - -with lib; - let cfg = config.services.mpdscribble; mpdCfg = config.services.mpd; @@ -22,7 +19,7 @@ let journal = /var/lib/mpdscribble/${secname}.journal ''; - endpoints = concatStringsSep "\n" (mapAttrsToList mkSection cfg.endpoints); + endpoints = lib.concatStringsSep "\n" (lib.mapAttrsToList mkSection cfg.endpoints); cfgTemplate = pkgs.writeText "mpdscribble.conf" '' ## This file was automatically genenrated by NixOS and will be overwritten. ## Do not edit. Edit your NixOS configuration instead. @@ -31,7 +28,7 @@ let ## http://mpd.wikia.com/wiki/Client:mpdscribble # HTTP proxy URL. - ${optionalString (cfg.proxy != null) "proxy = ${cfg.proxy}"} + ${lib.optionalString (cfg.proxy != null) "proxy = ${cfg.proxy}"} # The location of the mpdscribble log file. The special value # "syslog" makes mpdscribble use the local syslog daemon. On most @@ -47,7 +44,7 @@ let # The host running MPD, possibly protected by a password # ([PASSWORD@]HOSTNAME). - host = ${(optionalString (cfg.passwordFile != null) "{{MPD_PASSWORD}}@") + cfg.host} + host = ${(lib.optionalString (cfg.passwordFile != null) "{{MPD_PASSWORD}}@") + cfg.host} # The port that the MPD listens on and mpdscribble should try to # connect to. @@ -59,13 +56,13 @@ let cfgFile = "/run/mpdscribble/mpdscribble.conf"; replaceSecret = secretFile: placeholder: targetFile: - optionalString (secretFile != null) '' + lib.optionalString (secretFile != null) '' ${pkgs.replace-secret}/bin/replace-secret '${placeholder}' '${secretFile}' '${targetFile}' ''; preStart = pkgs.writeShellScript "mpdscribble-pre-start" '' cp -f "${cfgTemplate}" "${cfgFile}" ${replaceSecret cfg.passwordFile "{{MPD_PASSWORD}}" cfgFile} - ${concatStringsSep "\n" (mapAttrsToList (secname: cfg: + ${lib.concatStringsSep "\n" (lib.mapAttrsToList (secname: cfg: replaceSecret cfg.passwordFile "{{${secname}_PASSWORD}}" cfgFile) cfg.endpoints)} ''; @@ -77,62 +74,62 @@ in { options.services.mpdscribble = { - enable = mkEnableOption "mpdscribble, an MPD client which submits info about tracks being played to Last.fm (formerly AudioScrobbler)"; + enable = lib.mkEnableOption "mpdscribble, an MPD client which submits info about tracks being played to Last.fm (formerly AudioScrobbler)"; - proxy = mkOption { + proxy = lib.mkOption { default = null; - type = types.nullOr types.str; + type = lib.types.nullOr lib.types.str; description = '' HTTP proxy URL. ''; }; - verbose = mkOption { + verbose = lib.mkOption { default = 1; - type = types.int; + type = lib.types.int; description = '' Log level for the mpdscribble daemon. ''; }; - journalInterval = mkOption { + journalInterval = lib.mkOption { default = 600; example = 60; - type = types.int; + type = lib.types.int; description = '' How often should mpdscribble save the journal file? [seconds] ''; }; - host = mkOption { + host = lib.mkOption { default = (if mpdCfg.network.listenAddress != "any" then mpdCfg.network.listenAddress else "localhost"); - defaultText = literalExpression '' + defaultText = lib.literalExpression '' if config.${mpdOpt.network.listenAddress} != "any" then config.${mpdOpt.network.listenAddress} else "localhost" ''; - type = types.str; + type = lib.types.str; description = '' Host for the mpdscribble daemon to search for a mpd daemon on. ''; }; - passwordFile = mkOption { + passwordFile = lib.mkOption { default = if localMpd then - (findFirst - (c: any (x: x == "read") c.permissions) + (lib.findFirst + (c: lib.any (x: x == "read") c.permissions) { passwordFile = null; } mpdCfg.credentials).passwordFile else null; - defaultText = literalMD '' + defaultText = lib.literalMD '' The first password file with read access configured for MPD when using a local instance, otherwise `null`. ''; - type = types.nullOr types.str; + type = lib.types.nullOr lib.types.str; description = '' File containing the password for the mpd daemon. If there is a local mpd configured using {option}`services.mpd.credentials` @@ -140,37 +137,37 @@ in { ''; }; - port = mkOption { + port = lib.mkOption { default = mpdCfg.network.port; - defaultText = literalExpression "config.${mpdOpt.network.port}"; - type = types.port; + defaultText = lib.literalExpression "config.${mpdOpt.network.port}"; + type = lib.types.port; description = '' Port for the mpdscribble daemon to search for a mpd daemon on. ''; }; - endpoints = mkOption { + endpoints = lib.mkOption { type = (let endpoint = { name, ... }: { options = { - url = mkOption { - type = types.str; + url = lib.mkOption { + type = lib.types.str; default = endpointUrls.${name} or ""; description = "The url endpoint where the scrobble API is listening."; }; - username = mkOption { - type = types.str; + username = lib.mkOption { + type = lib.types.str; description = '' Username for the scrobble service. ''; }; - passwordFile = mkOption { - type = types.nullOr types.str; + passwordFile = lib.mkOption { + type = lib.types.nullOr lib.types.str; description = "File containing the password, either as MD5SUM or cleartext."; }; }; }; - in types.attrsOf (types.submodule endpoint)); + in lib.types.attrsOf (lib.types.submodule endpoint)); default = { }; example = { "last.fm" = { @@ -181,7 +178,7 @@ in { description = '' Endpoints to scrobble to. If the endpoint is one of "${ - concatStringsSep "\", \"" (attrNames endpointUrls) + lib.concatStringsSep "\", \"" (lib.attrNames endpointUrls) }" the url is set automatically. ''; }; @@ -190,9 +187,9 @@ in { ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.mpdscribble = { - after = [ "network.target" ] ++ (optional localMpd "mpd.service"); + after = [ "network.target" ] ++ (lib.optional localMpd "mpd.service"); description = "mpdscribble mpd scrobble client"; wantedBy = [ "multi-user.target" ]; serviceConfig = { From bde5fcc9b8b86976a8b55d66883f4809e3f205fe Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:37 +0200 Subject: [PATCH 052/166] nixos/services.networkaudiod: remove `with lib;` --- nixos/modules/services/audio/networkaudiod.nix | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/nixos/modules/services/audio/networkaudiod.nix b/nixos/modules/services/audio/networkaudiod.nix index 265a4e1d95d6..09e8fdcaacc3 100644 --- a/nixos/modules/services/audio/networkaudiod.nix +++ b/nixos/modules/services/audio/networkaudiod.nix @@ -1,18 +1,15 @@ { config, lib, pkgs, ... }: - -with lib; - let name = "networkaudiod"; cfg = config.services.networkaudiod; in { options = { services.networkaudiod = { - enable = mkEnableOption "Networkaudiod (NAA)"; + enable = lib.mkEnableOption "Networkaudiod (NAA)"; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.packages = [ pkgs.networkaudiod ]; systemd.services.networkaudiod.wantedBy = [ "multi-user.target" ]; }; From 794d3952b0e0ef789abfb09108f7f91de98d76c0 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:37 +0200 Subject: [PATCH 053/166] nixos/services.roon-bridge: remove `with lib;` --- nixos/modules/services/audio/roon-bridge.nix | 27 +++++++++----------- 1 file changed, 12 insertions(+), 15 deletions(-) diff --git a/nixos/modules/services/audio/roon-bridge.nix b/nixos/modules/services/audio/roon-bridge.nix index 218bbb2a4845..049e84f02f0c 100644 --- a/nixos/modules/services/audio/roon-bridge.nix +++ b/nixos/modules/services/audio/roon-bridge.nix @@ -1,30 +1,27 @@ { config, lib, pkgs, ... }: - -with lib; - let name = "roon-bridge"; cfg = config.services.roon-bridge; in { options = { services.roon-bridge = { - enable = mkEnableOption "Roon Bridge"; - openFirewall = mkOption { - type = types.bool; + enable = lib.mkEnableOption "Roon Bridge"; + openFirewall = lib.mkOption { + type = lib.types.bool; default = false; description = '' Open ports in the firewall for the bridge. ''; }; - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; default = "roon-bridge"; description = '' User to run the Roon bridge as. ''; }; - group = mkOption { - type = types.str; + group = lib.mkOption { + type = lib.types.str; default = "roon-bridge"; description = '' Group to run the Roon Bridge as. @@ -33,7 +30,7 @@ in { }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.roon-bridge = { after = [ "network.target" ]; description = "Roon Bridge"; @@ -50,17 +47,17 @@ in { }; }; - networking.firewall = mkIf cfg.openFirewall { + networking.firewall = lib.mkIf cfg.openFirewall { allowedTCPPortRanges = [{ from = 9100; to = 9200; }]; allowedUDPPorts = [ 9003 ]; - extraCommands = optionalString (!config.networking.nftables.enable) '' + extraCommands = lib.optionalString (!config.networking.nftables.enable) '' iptables -A INPUT -s 224.0.0.0/4 -j ACCEPT iptables -A INPUT -d 224.0.0.0/4 -j ACCEPT iptables -A INPUT -s 240.0.0.0/5 -j ACCEPT iptables -A INPUT -m pkttype --pkt-type multicast -j ACCEPT iptables -A INPUT -m pkttype --pkt-type broadcast -j ACCEPT ''; - extraInputRules = optionalString config.networking.nftables.enable '' + extraInputRules = lib.optionalString config.networking.nftables.enable '' ip saddr { 224.0.0.0/4, 240.0.0.0/5 } accept ip daddr 224.0.0.0/4 accept pkttype { multicast, broadcast } accept @@ -70,7 +67,7 @@ in { users.groups.${cfg.group} = {}; users.users.${cfg.user} = - optionalAttrs (cfg.user == "roon-bridge") { + lib.optionalAttrs (cfg.user == "roon-bridge") { isSystemUser = true; description = "Roon Bridge user"; group = cfg.group; From ecb168c8d7755a9f68b73b7a504518cb32f37495 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:38 +0200 Subject: [PATCH 054/166] nixos/services.roon-server: remove `with lib;` --- nixos/modules/services/audio/roon-server.nix | 27 +++++++++----------- 1 file changed, 12 insertions(+), 15 deletions(-) diff --git a/nixos/modules/services/audio/roon-server.nix b/nixos/modules/services/audio/roon-server.nix index d3b3752dd728..58763f5ceeeb 100644 --- a/nixos/modules/services/audio/roon-server.nix +++ b/nixos/modules/services/audio/roon-server.nix @@ -1,31 +1,28 @@ { config, lib, pkgs, ... }: - -with lib; - let name = "roon-server"; cfg = config.services.roon-server; in { options = { services.roon-server = { - enable = mkEnableOption "Roon Server"; + enable = lib.mkEnableOption "Roon Server"; package = lib.mkPackageOption pkgs "roon-server" { }; - openFirewall = mkOption { - type = types.bool; + openFirewall = lib.mkOption { + type = lib.types.bool; default = false; description = '' Open ports in the firewall for the server. ''; }; - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; default = "roon-server"; description = '' User to run the Roon Server as. ''; }; - group = mkOption { - type = types.str; + group = lib.mkOption { + type = lib.types.str; default = "roon-server"; description = '' Group to run the Roon Server as. @@ -34,7 +31,7 @@ in { }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.roon-server = { after = [ "network.target" ]; description = "Roon Server"; @@ -52,14 +49,14 @@ in { }; }; - networking.firewall = mkIf cfg.openFirewall { + networking.firewall = lib.mkIf cfg.openFirewall { allowedTCPPortRanges = [ { from = 9100; to = 9200; } { from = 9330; to = 9339; } { from = 30000; to = 30010; } ]; allowedUDPPorts = [ 9003 ]; - extraCommands = optionalString (!config.networking.nftables.enable) '' + extraCommands = lib.optionalString (!config.networking.nftables.enable) '' ## IGMP / Broadcast ## iptables -A INPUT -s 224.0.0.0/4 -j ACCEPT iptables -A INPUT -d 224.0.0.0/4 -j ACCEPT @@ -67,7 +64,7 @@ in { iptables -A INPUT -m pkttype --pkt-type multicast -j ACCEPT iptables -A INPUT -m pkttype --pkt-type broadcast -j ACCEPT ''; - extraInputRules = optionalString config.networking.nftables.enable '' + extraInputRules = lib.optionalString config.networking.nftables.enable '' ip saddr { 224.0.0.0/4, 240.0.0.0/5 } accept ip daddr 224.0.0.0/4 accept pkttype { multicast, broadcast } accept @@ -77,7 +74,7 @@ in { users.groups.${cfg.group} = {}; users.users.${cfg.user} = - optionalAttrs (cfg.user == "roon-server") { + lib.optionalAttrs (cfg.user == "roon-server") { isSystemUser = true; description = "Roon Server user"; group = cfg.group; From f6a10dfc095178af6a3020d5d789acea49dbc987 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:38 +0200 Subject: [PATCH 055/166] nixos/services.slimserver: remove `with lib;` --- nixos/modules/services/audio/slimserver.nix | 15 ++++++--------- 1 file changed, 6 insertions(+), 9 deletions(-) diff --git a/nixos/modules/services/audio/slimserver.nix b/nixos/modules/services/audio/slimserver.nix index a7f8968ef017..a9b5ed6bac00 100644 --- a/nixos/modules/services/audio/slimserver.nix +++ b/nixos/modules/services/audio/slimserver.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.slimserver; @@ -11,18 +8,18 @@ in { services.slimserver = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether to enable slimserver. ''; }; - package = mkPackageOption pkgs "slimserver" { }; + package = lib.mkPackageOption pkgs "slimserver" { }; - dataDir = mkOption { - type = types.path; + dataDir = lib.mkOption { + type = lib.types.path; default = "/var/lib/slimserver"; description = '' The directory where slimserver stores its state, tag cache, @@ -35,7 +32,7 @@ in { ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.tmpfiles.rules = [ "d '${cfg.dataDir}' - slimserver slimserver - -" From 9d80afc3c4d08a2a3ba1b156af53aaab3c1bbf07 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:38 +0200 Subject: [PATCH 056/166] nixos/services.spotifyd: remove `with lib;` --- nixos/modules/services/audio/spotifyd.nix | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-) diff --git a/nixos/modules/services/audio/spotifyd.nix b/nixos/modules/services/audio/spotifyd.nix index 60a7f0fd4e94..c44617a7d6d7 100644 --- a/nixos/modules/services/audio/spotifyd.nix +++ b/nixos/modules/services/audio/spotifyd.nix @@ -1,14 +1,11 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.spotifyd; toml = pkgs.formats.toml {}; warnConfig = if cfg.config != "" then lib.trace "Using the stringly typed .config attribute is discouraged. Use the TOML typed .settings attribute instead." - else id; + else lib.id; spotifydConf = if cfg.settings != {} then toml.generate "spotify.conf" cfg.settings @@ -17,18 +14,18 @@ in { options = { services.spotifyd = { - enable = mkEnableOption "spotifyd, a Spotify playing daemon"; + enable = lib.mkEnableOption "spotifyd, a Spotify playing daemon"; - config = mkOption { + config = lib.mkOption { default = ""; - type = types.lines; + type = lib.types.lines; description = '' (Deprecated) Configuration for Spotifyd. For syntax and directives, see . ''; }; - settings = mkOption { + settings = lib.mkOption { default = {}; type = toml.type; example = { global.bitrate = 320; }; @@ -40,7 +37,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { assertions = [ { assertion = cfg.config == "" || cfg.settings == {}; @@ -65,5 +62,5 @@ in }; }; - meta.maintainers = [ maintainers.anderslundstedt ]; + meta.maintainers = [ lib.maintainers.anderslundstedt ]; } From f600d6a3b162322731da51b0ecec4ee55d765dc8 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:39 +0200 Subject: [PATCH 057/166] nixos/services.ympd: remove `with lib;` --- nixos/modules/services/audio/ympd.nix | 21 +++++++++------------ 1 file changed, 9 insertions(+), 12 deletions(-) diff --git a/nixos/modules/services/audio/ympd.nix b/nixos/modules/services/audio/ympd.nix index ebbe59ca67c3..96977581a245 100644 --- a/nixos/modules/services/audio/ympd.nix +++ b/nixos/modules/services/audio/ympd.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.ympd; in { @@ -12,26 +9,26 @@ in { services.ympd = { - enable = mkEnableOption "ympd, the MPD Web GUI"; + enable = lib.mkEnableOption "ympd, the MPD Web GUI"; - webPort = mkOption { - type = types.either types.str types.port; # string for backwards compat + webPort = lib.mkOption { + type = lib.types.either lib.types.str lib.types.port; # string for backwards compat default = "8080"; description = "The port where ympd's web interface will be available."; example = "ssl://8080:/path/to/ssl-private-key.pem"; }; mpd = { - host = mkOption { - type = types.str; + host = lib.mkOption { + type = lib.types.str; default = "localhost"; description = "The host where MPD is listening."; }; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = config.services.mpd.network.port; - defaultText = literalExpression "config.services.mpd.network.port"; + defaultText = lib.literalExpression "config.services.mpd.network.port"; description = "The port where MPD is listening."; example = 6600; }; @@ -44,7 +41,7 @@ in { ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.ympd = { description = "Standalone MPD Web GUI written in C"; From ef50268985fdef382c2c990bc6395020edd771db Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:39 +0200 Subject: [PATCH 058/166] nixos/services.borgmatic: remove `with lib;` --- nixos/modules/services/backup/borgmatic.nix | 41 ++++++++++----------- 1 file changed, 19 insertions(+), 22 deletions(-) diff --git a/nixos/modules/services/backup/borgmatic.nix b/nixos/modules/services/backup/borgmatic.nix index 4d744a735582..1112182e8d23 100644 --- a/nixos/modules/services/backup/borgmatic.nix +++ b/nixos/modules/services/backup/borgmatic.nix @@ -1,20 +1,17 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.borgmatic; settingsFormat = pkgs.formats.yaml { }; - repository = with types; submodule { + repository = with lib.types; submodule { options = { - path = mkOption { + path = lib.mkOption { type = str; description = '' Path to the repository ''; }; - label = mkOption { + label = lib.mkOption { type = str; description = '' Label to the repository @@ -22,10 +19,10 @@ let }; }; }; - cfgType = with types; submodule { + cfgType = with lib.types; submodule { freeformType = settingsFormat.type; options = { - source_directories = mkOption { + source_directories = lib.mkOption { type = listOf str; default = []; description = '' @@ -34,7 +31,7 @@ let ''; example = [ "/home" "/etc" "/var/log/syslog*" "/home/user/path with spaces" ]; }; - repositories = mkOption { + repositories = lib.mkOption { type = listOf repository; default = []; description = '' @@ -59,33 +56,33 @@ let in { options.services.borgmatic = { - enable = mkEnableOption "borgmatic"; + enable = lib.mkEnableOption "borgmatic"; - settings = mkOption { + settings = lib.mkOption { description = '' See https://torsion.org/borgmatic/docs/reference/configuration/ ''; default = null; - type = types.nullOr cfgType; + type = lib.types.nullOr cfgType; }; - configurations = mkOption { + configurations = lib.mkOption { description = '' Set of borgmatic configurations, see https://torsion.org/borgmatic/docs/reference/configuration/ ''; default = { }; - type = types.attrsOf cfgType; + type = lib.types.attrsOf cfgType; }; - enableConfigCheck = mkEnableOption "checking all configurations during build time" // { default = true; }; + enableConfigCheck = lib.mkEnableOption "checking all configurations during build time" // { default = true; }; }; config = let configFiles = - (optionalAttrs (cfg.settings != null) { "borgmatic/config.yaml".source = cfgfile; }) // - mapAttrs' - (name: value: nameValuePair + (lib.optionalAttrs (cfg.settings != null) { "borgmatic/config.yaml".source = cfgfile; }) // + lib.mapAttrs' + (name: value: lib.nameValuePair "borgmatic.d/${name}.yaml" { source = settingsFormat.generate "${name}.yaml" value; }) cfg.configurations; @@ -94,12 +91,12 @@ in touch $out ''; in - mkIf cfg.enable { + lib.mkIf cfg.enable { warnings = [] - ++ optional (cfg.settings != null && cfg.settings ? location) + ++ lib.optional (cfg.settings != null && cfg.settings ? location) "`services.borgmatic.settings.location` is deprecated, please move your options out of sections to the global scope" - ++ optional (catAttrs "location" (attrValues cfg.configurations) != []) + ++ lib.optional (lib.catAttrs "location" (lib.attrValues cfg.configurations) != []) "`services.borgmatic.configurations..location` is deprecated, please move your options out of sections to the global scope" ; @@ -112,6 +109,6 @@ in # Workaround: https://github.com/NixOS/nixpkgs/issues/81138 systemd.timers.borgmatic.wantedBy = [ "timers.target" ]; - system.checks = mkIf cfg.enableConfigCheck (mapAttrsToList borgmaticCheck configFiles); + system.checks = lib.mkIf cfg.enableConfigCheck (lib.mapAttrsToList borgmaticCheck configFiles); }; } From 699a0f8601c7aaab84c9fd38ebff438165f28791 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:40 +0200 Subject: [PATCH 059/166] nixos/services.duplicati: remove `with lib;` --- nixos/modules/services/backup/duplicati.nix | 29 +++++++++------------ 1 file changed, 13 insertions(+), 16 deletions(-) diff --git a/nixos/modules/services/backup/duplicati.nix b/nixos/modules/services/backup/duplicati.nix index 2b9e171d7d80..85f508141ba7 100644 --- a/nixos/modules/services/backup/duplicati.nix +++ b/nixos/modules/services/backup/duplicati.nix @@ -1,27 +1,24 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.services.duplicati; in { options = { services.duplicati = { - enable = mkEnableOption "Duplicati"; + enable = lib.mkEnableOption "Duplicati"; - package = mkPackageOption pkgs "duplicati" { }; + package = lib.mkPackageOption pkgs "duplicati" { }; - port = mkOption { + port = lib.mkOption { default = 8200; - type = types.port; + type = lib.types.port; description = '' Port serving the web interface ''; }; - dataDir = mkOption { - type = types.str; + dataDir = lib.mkOption { + type = lib.types.str; default = "/var/lib/duplicati"; description = '' The directory where Duplicati stores its data files. @@ -34,18 +31,18 @@ in ''; }; - interface = mkOption { + interface = lib.mkOption { default = "127.0.0.1"; - type = types.str; + type = lib.types.str; description = '' Listening interface for the web UI Set it to "any" to listen on all available interfaces ''; }; - user = mkOption { + user = lib.mkOption { default = "duplicati"; - type = types.str; + type = lib.types.str; description = '' Duplicati runs as it's own user. It will only be able to backup world-readable files. Run as root with special care. @@ -54,21 +51,21 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = [ cfg.package ]; systemd.services.duplicati = { description = "Duplicati backup"; after = [ "network.target" ]; wantedBy = [ "multi-user.target" ]; - serviceConfig = mkMerge [ + serviceConfig = lib.mkMerge [ { User = cfg.user; Group = "duplicati"; ExecStart = "${cfg.package}/bin/duplicati-server --webservice-interface=${cfg.interface} --webservice-port=${toString cfg.port} --server-datafolder=${cfg.dataDir}"; Restart = "on-failure"; } - (mkIf (cfg.dataDir == "/var/lib/duplicati") { + (lib.mkIf (cfg.dataDir == "/var/lib/duplicati") { StateDirectory = "duplicati"; }) ]; From 01218209dc20cfc9e56333f4a57c462b8639d346 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:40 +0200 Subject: [PATCH 060/166] nixos/services.duplicity: remove `with lib;` --- nixos/modules/services/backup/duplicity.nix | 80 ++++++++++----------- 1 file changed, 39 insertions(+), 41 deletions(-) diff --git a/nixos/modules/services/backup/duplicity.nix b/nixos/modules/services/backup/duplicity.nix index 46625ec5460e..d6927d63ca7a 100644 --- a/nixos/modules/services/backup/duplicity.nix +++ b/nixos/modules/services/backup/duplicity.nix @@ -1,30 +1,28 @@ { config, lib, pkgs, ... }: - -with lib; let cfg = config.services.duplicity; stateDirectory = "/var/lib/duplicity"; localTarget = - if hasPrefix "file://" cfg.targetUrl - then removePrefix "file://" cfg.targetUrl else null; + if lib.hasPrefix "file://" cfg.targetUrl + then lib.removePrefix "file://" cfg.targetUrl else null; in { options.services.duplicity = { - enable = mkEnableOption "backups with duplicity"; + enable = lib.mkEnableOption "backups with duplicity"; - root = mkOption { - type = types.path; + root = lib.mkOption { + type = lib.types.path; default = "/"; description = '' Root directory to backup. ''; }; - include = mkOption { - type = types.listOf types.str; + include = lib.mkOption { + type = lib.types.listOf lib.types.str; default = [ ]; example = [ "/home" ]; description = '' @@ -33,8 +31,8 @@ in ''; }; - exclude = mkOption { - type = types.listOf types.str; + exclude = lib.mkOption { + type = lib.types.listOf lib.types.str; default = [ ]; description = '' List of paths to exclude from backups. See the FILE SELECTION section in @@ -42,8 +40,8 @@ in ''; }; - includeFileList = mkOption { - type = types.nullOr types.path; + includeFileList = lib.mkOption { + type = lib.types.nullOr lib.types.path; default = null; example = /path/to/fileList.txt; description = '' @@ -53,8 +51,8 @@ in ''; }; - excludeFileList = mkOption { - type = types.nullOr types.path; + excludeFileList = lib.mkOption { + type = lib.types.nullOr lib.types.path; default = null; example = /path/to/fileList.txt; description = '' @@ -64,8 +62,8 @@ in ''; }; - targetUrl = mkOption { - type = types.str; + targetUrl = lib.mkOption { + type = lib.types.str; example = "s3://host:port/prefix"; description = '' Target url to backup to. See the URL FORMAT section in @@ -73,8 +71,8 @@ in ''; }; - secretFile = mkOption { - type = types.nullOr types.path; + secretFile = lib.mkOption { + type = lib.types.nullOr lib.types.path; default = null; description = '' Path of a file containing secrets (gpg passphrase, access key...) in @@ -88,8 +86,8 @@ in ''; }; - frequency = mkOption { - type = types.nullOr types.str; + frequency = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = "daily"; description = '' Run duplicity with the given frequency (see @@ -98,8 +96,8 @@ in ''; }; - extraFlags = mkOption { - type = types.listOf types.str; + extraFlags = lib.mkOption { + type = lib.types.listOf lib.types.str; default = [ ]; example = [ "--backend-retry-delay" "100" ]; description = '' @@ -108,8 +106,8 @@ in ''; }; - fullIfOlderThan = mkOption { - type = types.str; + fullIfOlderThan = lib.mkOption { + type = lib.types.str; default = "never"; example = "1M"; description = '' @@ -123,8 +121,8 @@ in }; cleanup = { - maxAge = mkOption { - type = types.nullOr types.str; + maxAge = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; example = "6M"; description = '' @@ -132,8 +130,8 @@ in will not be deleted if backup sets newer than time depend on them. ''; }; - maxFull = mkOption { - type = types.nullOr types.int; + maxFull = lib.mkOption { + type = lib.types.nullOr lib.types.int; default = null; example = 2; description = '' @@ -142,8 +140,8 @@ in associated incremental sets). ''; }; - maxIncr = mkOption { - type = types.nullOr types.int; + maxIncr = lib.mkOption { + type = lib.types.nullOr lib.types.int; default = null; example = 1; description = '' @@ -155,7 +153,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd = { services.duplicity = { description = "backup files with duplicity"; @@ -164,8 +162,8 @@ in script = let - target = escapeShellArg cfg.targetUrl; - extra = escapeShellArgs ([ "--archive-dir" stateDirectory ] ++ cfg.extraFlags); + target = lib.escapeShellArg cfg.targetUrl; + extra = lib.escapeShellArgs ([ "--archive-dir" stateDirectory ] ++ cfg.extraFlags); dup = "${pkgs.duplicity}/bin/duplicity"; in '' @@ -178,8 +176,8 @@ in [ cfg.root cfg.targetUrl ] ++ lib.optionals (cfg.includeFileList != null) [ "--include-filelist" cfg.includeFileList ] ++ lib.optionals (cfg.excludeFileList != null) [ "--exclude-filelist" cfg.excludeFileList ] - ++ concatMap (p: [ "--include" p ]) cfg.include - ++ concatMap (p: [ "--exclude" p ]) cfg.exclude + ++ lib.concatMap (p: [ "--include" p ]) cfg.include + ++ lib.concatMap (p: [ "--exclude" p ]) cfg.exclude ++ (lib.optionals (cfg.fullIfOlderThan != "never" && cfg.fullIfOlderThan != "always") [ "--full-if-older-than" cfg.fullIfOlderThan ]) )} ${extra} ''; @@ -188,19 +186,19 @@ in ProtectSystem = "strict"; ProtectHome = "read-only"; StateDirectory = baseNameOf stateDirectory; - } // optionalAttrs (localTarget != null) { + } // lib.optionalAttrs (localTarget != null) { ReadWritePaths = localTarget; - } // optionalAttrs (cfg.secretFile != null) { + } // lib.optionalAttrs (cfg.secretFile != null) { EnvironmentFile = cfg.secretFile; }; - } // optionalAttrs (cfg.frequency != null) { + } // lib.optionalAttrs (cfg.frequency != null) { startAt = cfg.frequency; }; - tmpfiles.rules = optional (localTarget != null) "d ${localTarget} 0700 root root -"; + tmpfiles.rules = lib.optional (localTarget != null) "d ${localTarget} 0700 root root -"; }; - assertions = singleton { + assertions = lib.singleton { # Duplicity will fail if the last file selection option is an include. It # is not always possible to detect but this simple case can be caught. assertion = cfg.include != [ ] -> cfg.exclude != [ ] || cfg.extraFlags != [ ]; From 9540ed87477e6603ef62b4748ecab203b6dabcc7 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:40 +0200 Subject: [PATCH 061/166] nixos/services.paperless: remove `with lib;` --- nixos/modules/services/misc/paperless.nix | 82 +++++++++++------------ 1 file changed, 40 insertions(+), 42 deletions(-) diff --git a/nixos/modules/services/misc/paperless.nix b/nixos/modules/services/misc/paperless.nix index 3dfe3b87cae1..cbbd8b534504 100644 --- a/nixos/modules/services/misc/paperless.nix +++ b/nixos/modules/services/misc/paperless.nix @@ -1,6 +1,4 @@ { config, pkgs, lib, ... }: - -with lib; let cfg = config.services.paperless; @@ -17,16 +15,16 @@ let PAPERLESS_CONSUMPTION_DIR = cfg.consumptionDir; PAPERLESS_THUMBNAIL_FONT_NAME = defaultFont; GUNICORN_CMD_ARGS = "--bind=${cfg.address}:${toString cfg.port}"; - } // optionalAttrs (config.time.timeZone != null) { + } // lib.optionalAttrs (config.time.timeZone != null) { PAPERLESS_TIME_ZONE = config.time.timeZone; - } // optionalAttrs enableRedis { + } // lib.optionalAttrs enableRedis { PAPERLESS_REDIS = "unix://${redisServer.unixSocket}"; - } // optionalAttrs (cfg.settings.PAPERLESS_ENABLE_NLTK or true) { + } // lib.optionalAttrs (cfg.settings.PAPERLESS_ENABLE_NLTK or true) { PAPERLESS_NLTK_DIR = pkgs.symlinkJoin { name = "paperless_ngx_nltk_data"; paths = cfg.package.nltkData; }; - } // optionalAttrs (cfg.openMPThreadingWorkaround) { + } // lib.optionalAttrs (cfg.openMPThreadingWorkaround) { OMP_NUM_THREADS = "1"; } // (lib.mapAttrs (_: s: if (lib.isAttrs s || lib.isList s) then builtins.toJSON s @@ -53,7 +51,7 @@ let CapabilityBoundingSet = ""; # ProtectClock adds DeviceAllow=char-rtc r DeviceAllow = ""; - EnvironmentFile = mkIf (cfg.environmentFile != null) cfg.environmentFile; + EnvironmentFile = lib.mkIf (cfg.environmentFile != null) cfg.environmentFile; LockPersonality = true; MemoryDenyWriteExecute = true; NoNewPrivileges = true; @@ -80,22 +78,22 @@ let RestrictNamespaces = true; RestrictRealtime = true; RestrictSUIDSGID = true; - SupplementaryGroups = optional enableRedis redisServer.user; + SupplementaryGroups = lib.optional enableRedis redisServer.user; SystemCallArchitectures = "native"; SystemCallFilter = [ "@system-service" "~@privileged @setuid @keyring" ]; UMask = "0066"; }; in { - meta.maintainers = with maintainers; [ leona SuperSandro2000 erikarvstedt ]; + meta.maintainers = with lib.maintainers; [ leona SuperSandro2000 erikarvstedt ]; imports = [ - (mkRenamedOptionModule [ "services" "paperless-ng" ] [ "services" "paperless" ]) - (mkRenamedOptionModule [ "services" "paperless" "extraConfig" ] [ "services" "paperless" "settings" ]) + (lib.mkRenamedOptionModule [ "services" "paperless-ng" ] [ "services" "paperless" ]) + (lib.mkRenamedOptionModule [ "services" "paperless" "extraConfig" ] [ "services" "paperless" "settings" ]) ]; options.services.paperless = { - enable = mkOption { + enable = lib.mkOption { type = lib.types.bool; default = false; description = '' @@ -110,34 +108,34 @@ in ''; }; - dataDir = mkOption { - type = types.str; + dataDir = lib.mkOption { + type = lib.types.str; default = "/var/lib/paperless"; description = "Directory to store the Paperless data."; }; - mediaDir = mkOption { - type = types.str; + mediaDir = lib.mkOption { + type = lib.types.str; default = "${cfg.dataDir}/media"; - defaultText = literalExpression ''"''${dataDir}/media"''; + defaultText = lib.literalExpression ''"''${dataDir}/media"''; description = "Directory to store the Paperless documents."; }; - consumptionDir = mkOption { - type = types.str; + consumptionDir = lib.mkOption { + type = lib.types.str; default = "${cfg.dataDir}/consume"; - defaultText = literalExpression ''"''${dataDir}/consume"''; + defaultText = lib.literalExpression ''"''${dataDir}/consume"''; description = "Directory from which new documents are imported."; }; - consumptionDirIsPublic = mkOption { - type = types.bool; + consumptionDirIsPublic = lib.mkOption { + type = lib.types.bool; default = false; description = "Whether all users can write to the consumption dir."; }; - passwordFile = mkOption { - type = types.nullOr types.path; + passwordFile = lib.mkOption { + type = lib.types.nullOr lib.types.path; default = null; example = "/run/keys/paperless-password"; description = '' @@ -158,19 +156,19 @@ in ''; }; - address = mkOption { - type = types.str; + address = lib.mkOption { + type = lib.types.str; default = "localhost"; description = "Web interface address."; }; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 28981; description = "Web interface port."; }; - settings = mkOption { + settings = lib.mkOption { type = lib.types.submodule { freeformType = with lib.types; attrsOf (let typeList = [ bool float int str path package ]; @@ -196,19 +194,19 @@ in }; }; - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; default = defaultUser; description = "User under which Paperless runs."; }; - package = mkPackageOption pkgs "paperless-ngx" { } // { + package = lib.mkPackageOption pkgs "paperless-ngx" { } // { apply = pkg: pkg.override { tesseract5 = pkg.tesseract5.override { # always enable detection modules # tesseract fails to build when eng is not present enableLanguages = if cfg.settings ? PAPERLESS_OCR_LANGUAGE then - lists.unique ( + lib.lists.unique ( [ "equ" "osd" "eng" ] ++ lib.splitString "+" cfg.settings.PAPERLESS_OCR_LANGUAGE ) @@ -217,7 +215,7 @@ in }; }; - openMPThreadingWorkaround = mkEnableOption '' + openMPThreadingWorkaround = lib.mkEnableOption '' a workaround for document classifier timeouts. Paperless uses OpenBLAS via scikit-learn for document classification. @@ -229,10 +227,10 @@ in This sets `OMP_NUM_THREADS` to `1` in order to mitigate the issue. See https://github.com/NixOS/nixpkgs/issues/240591 for more information - '' // mkOption { default = true; }; + '' // lib.mkOption { default = true; }; - environmentFile = mkOption { - type = types.nullOr lib.types.path; + environmentFile = lib.mkOption { + type = lib.types.nullOr lib.types.path; default = null; example = "/run/secrets/paperless"; description = '' @@ -250,8 +248,8 @@ in }; }; - config = mkIf cfg.enable { - services.redis.servers.paperless.enable = mkIf enableRedis true; + config = lib.mkIf cfg.enable { + services.redis.servers.paperless.enable = lib.mkIf enableRedis true; systemd.slices.system-paperless = { description = "Paperless Document Management System Slice"; @@ -308,7 +306,7 @@ in echo ${cfg.package.version} > "$versionFile" fi '' - + optionalString (cfg.passwordFile != null) '' + + lib.optionalString (cfg.passwordFile != null) '' export PAPERLESS_ADMIN_USER="''${PAPERLESS_ADMIN_USER:-admin}" PAPERLESS_ADMIN_PASSWORD=$(cat "$CREDENTIALS_DIRECTORY/PAPERLESS_ADMIN_PASSWORD") export PAPERLESS_ADMIN_PASSWORD @@ -320,7 +318,7 @@ in echo "$superuserState" > "$superuserStateFile" fi ''; - } // optionalAttrs enableRedis { + } // lib.optionalAttrs enableRedis { after = [ "redis-paperless.service" ]; }; @@ -401,7 +399,7 @@ in unitConfig.JoinsNamespaceOf = "paperless-task-queue.service"; }; - users = optionalAttrs (cfg.user == defaultUser) { + users = lib.optionalAttrs (cfg.user == defaultUser) { users.${defaultUser} = { group = defaultUser; uid = config.ids.uids.paperless; From 59061eb9ea8bc76ed8abb83df970172685296e13 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:40 +0200 Subject: [PATCH 062/166] nixos/services.parsoid: remove `with lib;` --- nixos/modules/services/misc/parsoid.nix | 35 +++++++++++-------------- 1 file changed, 16 insertions(+), 19 deletions(-) diff --git a/nixos/modules/services/misc/parsoid.nix b/nixos/modules/services/misc/parsoid.nix index a1935d202172..bb168c4eca85 100644 --- a/nixos/modules/services/misc/parsoid.nix +++ b/nixos/modules/services/misc/parsoid.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.parsoid; @@ -15,19 +12,19 @@ let module = "lib/index.js"; entrypoint = "apiServiceWorker"; conf = { - mwApis = map (x: if isAttrs x then x else { uri = x; }) cfg.wikis; + mwApis = map (x: if lib.isAttrs x then x else { uri = x; }) cfg.wikis; serverInterface = cfg.interface; serverPort = cfg.port; }; }]; }; - confFile = pkgs.writeText "config.yml" (builtins.toJSON (recursiveUpdate confTree cfg.extraConfig)); + confFile = pkgs.writeText "config.yml" (builtins.toJSON (lib.recursiveUpdate confTree cfg.extraConfig)); in { imports = [ - (mkRemovedOptionModule [ "services" "parsoid" "interwikis" ] "Use services.parsoid.wikis instead") + (lib.mkRemovedOptionModule [ "services" "parsoid" "interwikis" ] "Use services.parsoid.wikis instead") ]; ##### interface @@ -36,8 +33,8 @@ in services.parsoid = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether to enable Parsoid -- bidirectional @@ -45,40 +42,40 @@ in ''; }; - wikis = mkOption { - type = types.listOf (types.either types.str types.attrs); + wikis = lib.mkOption { + type = lib.types.listOf (lib.types.either lib.types.str lib.types.attrs); example = [ "http://localhost/api.php" ]; description = '' Used MediaWiki API endpoints. ''; }; - workers = mkOption { - type = types.int; + workers = lib.mkOption { + type = lib.types.int; default = 2; description = '' Number of Parsoid workers. ''; }; - interface = mkOption { - type = types.str; + interface = lib.mkOption { + type = lib.types.str; default = "127.0.0.1"; description = '' Interface to listen on. ''; }; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 8000; description = '' Port to listen on. ''; }; - extraConfig = mkOption { - type = types.attrs; + extraConfig = lib.mkOption { + type = lib.types.attrs; default = {}; description = '' Extra configuration to add to parsoid configuration. @@ -91,7 +88,7 @@ in ##### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.parsoid = { description = "Bidirectional wikitext parser"; From bb74224921fb9f69c3382180be9399f5b57014a1 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:41 +0200 Subject: [PATCH 063/166] nixos/services.pinnwand: remove `with lib;` --- nixos/modules/services/misc/pinnwand.nix | 31 +++++++++++------------- 1 file changed, 14 insertions(+), 17 deletions(-) diff --git a/nixos/modules/services/misc/pinnwand.nix b/nixos/modules/services/misc/pinnwand.nix index 9c26864dab56..3a5c47aeefd2 100644 --- a/nixos/modules/services/misc/pinnwand.nix +++ b/nixos/modules/services/misc/pinnwand.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.pinnwand; @@ -10,25 +7,25 @@ let in { options.services.pinnwand = { - enable = mkEnableOption "Pinnwand, a pastebin"; + enable = lib.mkEnableOption "Pinnwand, a pastebin"; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; description = "The port to listen on."; default = 8000; }; - settings = mkOption { + settings = lib.mkOption { default = {}; description = '' Your {file}`pinnwand.toml` as a Nix attribute set. Look up possible options in the [documentation](https://pinnwand.readthedocs.io/en/v${pkgs.pinnwand.version}/configuration.html). ''; - type = types.submodule { + type = lib.types.submodule { freeformType = format.type; options = { - database_uri = mkOption { - type = types.str; + database_uri = lib.mkOption { + type = lib.types.str; default = "sqlite:////var/lib/pinnwand/pinnwand.db"; example = "sqlite:///:memory"; description = '' @@ -38,16 +35,16 @@ in ''; }; - paste_size = mkOption { - type = types.ints.positive; + paste_size = lib.mkOption { + type = lib.types.ints.positive; default = 262144; example = 524288; description = '' Maximum size of a paste in bytes. ''; }; - paste_help = mkOption { - type = types.str; + paste_help = lib.mkOption { + type = lib.types.str; default = ''

Welcome to pinnwand, this site is a pastebin. It allows you to share code with others. If you write code in the text area below and press the paste button you will be given a link you can share with others so they can view your code as well.

People with the link can view your pasted code, only you can remove your paste and it expires automatically. Note that anyone could guess the URI to your paste so don't rely on it being private.

''; @@ -55,8 +52,8 @@ in Raw HTML help text shown in the header area. ''; }; - footer = mkOption { - type = types.str; + footer = lib.mkOption { + type = lib.types.str; default = '' View source code, the removal or expiry stories, or read the about page. ''; @@ -69,7 +66,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.pinnwand = { description = "Pinnwannd HTTP Server"; after = [ "network.target" ]; From 8553d979a176b9aa8b05d747268184f9b4d4aaea Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:41 +0200 Subject: [PATCH 064/166] nixos/services.plex: remove `with lib;` --- nixos/modules/services/misc/plex.nix | 55 +++++++++++++--------------- 1 file changed, 26 insertions(+), 29 deletions(-) diff --git a/nixos/modules/services/misc/plex.nix b/nixos/modules/services/misc/plex.nix index 212abda5d1e0..d1524aaae2a3 100644 --- a/nixos/modules/services/misc/plex.nix +++ b/nixos/modules/services/misc/plex.nix @@ -1,53 +1,50 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.services.plex; in { imports = [ - (mkRemovedOptionModule [ "services" "plex" "managePlugins" ] "Please omit or define the option: `services.plex.extraPlugins' instead.") + (lib.mkRemovedOptionModule [ "services" "plex" "managePlugins" ] "Please omit or define the option: `services.plex.extraPlugins' instead.") ]; options = { services.plex = { - enable = mkEnableOption "Plex Media Server"; + enable = lib.mkEnableOption "Plex Media Server"; - dataDir = mkOption { - type = types.str; + dataDir = lib.mkOption { + type = lib.types.str; default = "/var/lib/plex"; description = '' The directory where Plex stores its data files. ''; }; - openFirewall = mkOption { - type = types.bool; + openFirewall = lib.mkOption { + type = lib.types.bool; default = false; description = '' Open ports in the firewall for the media server. ''; }; - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; default = "plex"; description = '' User account under which Plex runs. ''; }; - group = mkOption { - type = types.str; + group = lib.mkOption { + type = lib.types.str; default = "plex"; description = '' Group under which Plex runs. ''; }; - extraPlugins = mkOption { - type = types.listOf types.path; + extraPlugins = lib.mkOption { + type = lib.types.listOf lib.types.path; default = []; description = '' A list of paths to extra plugin bundles to install in Plex's plugin @@ -55,7 +52,7 @@ in symlinks in Plex's plugin directory will be cleared and this module will symlink all of the paths specified here to that directory. ''; - example = literalExpression '' + example = lib.literalExpression '' [ (builtins.path { name = "Audnexus.bundle"; @@ -70,8 +67,8 @@ in ''; }; - extraScanners = mkOption { - type = types.listOf types.path; + extraScanners = lib.mkOption { + type = lib.types.listOf lib.types.path; default = []; description = '' A list of paths to extra scanners to install in Plex's scanners @@ -81,7 +78,7 @@ in in Plex's scanners directory will be cleared and this module will symlink all of the paths specified here to that directory. ''; - example = literalExpression '' + example = lib.literalExpression '' [ (fetchFromGitHub { owner = "ZeroQI"; @@ -93,8 +90,8 @@ in ''; }; - accelerationDevices = mkOption { - type = types.listOf types.str; + accelerationDevices = lib.mkOption { + type = lib.types.listOf lib.types.str; default = ["*"]; example = [ "/dev/dri/renderD128" ]; description = '' @@ -104,7 +101,7 @@ in ''; }; - package = mkPackageOption pkgs "plex" { + package = lib.mkPackageOption pkgs "plex" { extraDescription = '' Plex subscribers may wish to use their own package here, pointing to subscriber-only server versions. @@ -113,7 +110,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { # Most of this is just copied from the RPM package's systemd service file. systemd.services.plex = { description = "Plex Media Server"; @@ -149,7 +146,7 @@ in NoNewPrivileges = true; PrivateTmp = true; PrivateDevices = cfg.accelerationDevices == []; - DeviceAllow = mkIf (cfg.accelerationDevices != [] && !lib.elem "*" cfg.accelerationDevices) cfg.accelerationDevices; + DeviceAllow = lib.mkIf (cfg.accelerationDevices != [] && !lib.elem "*" cfg.accelerationDevices) cfg.accelerationDevices; ProtectSystem = true; ProtectHome = true; ProtectControlGroups = true; @@ -167,8 +164,8 @@ in environment = { # Configuration for our FHS userenv script PLEX_DATADIR=cfg.dataDir; - PLEX_PLUGINS=concatMapStringsSep ":" builtins.toString cfg.extraPlugins; - PLEX_SCANNERS=concatMapStringsSep ":" builtins.toString cfg.extraScanners; + PLEX_PLUGINS=lib.concatMapStringsSep ":" builtins.toString cfg.extraPlugins; + PLEX_SCANNERS=lib.concatMapStringsSep ":" builtins.toString cfg.extraScanners; # The following variables should be set by the FHS userenv script: # PLEX_MEDIA_SERVER_APPLICATION_SUPPORT_DIR @@ -186,19 +183,19 @@ in }; }; - networking.firewall = mkIf cfg.openFirewall { + networking.firewall = lib.mkIf cfg.openFirewall { allowedTCPPorts = [ 32400 3005 8324 32469 ]; allowedUDPPorts = [ 1900 5353 32410 32412 32413 32414 ]; }; - users.users = mkIf (cfg.user == "plex") { + users.users = lib.mkIf (cfg.user == "plex") { plex = { group = cfg.group; uid = config.ids.uids.plex; }; }; - users.groups = mkIf (cfg.group == "plex") { + users.groups = lib.mkIf (cfg.group == "plex") { plex = { gid = config.ids.gids.plex; }; From 66fecabb5fe0615253775114b6a6db235eda87fd Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:41 +0200 Subject: [PATCH 065/166] nixos/services.plikd: remove `with lib;` --- nixos/modules/services/misc/plikd.nix | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-) diff --git a/nixos/modules/services/misc/plikd.nix b/nixos/modules/services/misc/plikd.nix index ec94cfc02979..477c1b413fd0 100644 --- a/nixos/modules/services/misc/plikd.nix +++ b/nixos/modules/services/misc/plikd.nix @@ -1,7 +1,4 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.services.plikd; @@ -11,15 +8,15 @@ in { options = { services.plikd = { - enable = mkEnableOption "plikd, a temporary file upload system"; + enable = lib.mkEnableOption "plikd, a temporary file upload system"; - openFirewall = mkOption { - type = types.bool; + openFirewall = lib.mkOption { + type = lib.types.bool; default = false; description = "Open ports in the firewall for the plikd."; }; - settings = mkOption { + settings = lib.mkOption { type = format.type; default = {}; description = '' @@ -30,8 +27,8 @@ in }; }; - config = mkIf cfg.enable { - services.plikd.settings = mapAttrs (name: mkDefault) { + config = lib.mkIf cfg.enable { + services.plikd.settings = lib.mapAttrs (name: lib.mkDefault) { ListenPort = 8080; ListenAddress = "localhost"; DataBackend = "file"; @@ -75,7 +72,7 @@ in }; }; - networking.firewall = mkIf cfg.openFirewall { + networking.firewall = lib.mkIf cfg.openFirewall { allowedTCPPorts = [ cfg.settings.ListenPort ]; }; }; From 257f608dfcb1ab49d655c1cf6056aff7085d57ba Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:42 +0200 Subject: [PATCH 066/166] nixos/services.polaris: remove `with lib;` --- nixos/modules/services/misc/polaris.nix | 42 ++++++++++++------------- 1 file changed, 20 insertions(+), 22 deletions(-) diff --git a/nixos/modules/services/misc/polaris.nix b/nixos/modules/services/misc/polaris.nix index 4ac99eaad384..70c478d193e9 100644 --- a/nixos/modules/services/misc/polaris.nix +++ b/nixos/modules/services/misc/polaris.nix @@ -2,8 +2,6 @@ , pkgs , lib , ...}: - -with lib; let cfg = config.services.polaris; settingsFormat = pkgs.formats.toml {}; @@ -11,31 +9,31 @@ in { options = { services.polaris = { - enable = mkEnableOption "Polaris Music Server"; + enable = lib.mkEnableOption "Polaris Music Server"; - package = mkPackageOption pkgs "polaris" { }; + package = lib.mkPackageOption pkgs "polaris" { }; - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; default = "polaris"; description = "User account under which Polaris runs."; }; - group = mkOption { - type = types.str; + group = lib.mkOption { + type = lib.types.str; default = "polaris"; description = "Group under which Polaris is run."; }; - extraGroups = mkOption { - type = types.listOf types.str; + extraGroups = lib.mkOption { + type = lib.types.listOf lib.types.str; default = []; description = "Polaris' auxiliary groups."; - example = literalExpression ''["media" "music"]''; + example = lib.literalExpression ''["media" "music"]''; }; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 5050; description = '' The port which the Polaris REST api and web UI should listen to. @@ -43,7 +41,7 @@ in ''; }; - settings = mkOption { + settings = lib.mkOption { type = settingsFormat.type; default = {}; description = '' @@ -51,7 +49,7 @@ in Although poorly documented, an example may be found here: [test-config.toml](https://github.com/agersant/polaris/blob/374d0ca56fc0a466d797a4b252e2078607476797/test-data/config.toml) ''; - example = literalExpression '' + example = lib.literalExpression '' { settings.reindex_every_n_seconds = 7*24*60*60; # weekly, default is 1800 settings.album_art_pattern = @@ -70,8 +68,8 @@ in ''; }; - openFirewall = mkOption { - type = types.bool; + openFirewall = lib.mkOption { + type = lib.types.bool; default = false; description = '' Open the configured port in the firewall. @@ -80,7 +78,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.polaris = { description = "Polaris Music Server"; after = [ "network.target" ]; @@ -93,13 +91,13 @@ in SupplementaryGroups = cfg.extraGroups; StateDirectory = "polaris"; CacheDirectory = "polaris"; - ExecStart = escapeShellArgs ([ + ExecStart = lib.escapeShellArgs ([ "${cfg.package}/bin/polaris" "--foreground" "--port" cfg.port "--database" "/var/lib/${StateDirectory}/db.sqlite" "--cache" "/var/cache/${CacheDirectory}" - ] ++ optionals (cfg.settings != {}) [ + ] ++ lib.optionals (cfg.settings != {}) [ "--config" (settingsFormat.generate "polaris-config.toml" cfg.settings) ]); Restart = "on-failure"; @@ -141,11 +139,11 @@ in }; }; - networking.firewall = mkIf cfg.openFirewall { + networking.firewall = lib.mkIf cfg.openFirewall { allowedTCPPorts = [ cfg.port ]; }; }; - meta.maintainers = with maintainers; [ pbsds ]; + meta.maintainers = with lib.maintainers; [ pbsds ]; } From 6a73a0aca934dd4fff87a4d5eeeb86bfab44bfb0 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:42 +0200 Subject: [PATCH 067/166] nixos/services.preload: remove `with lib;` --- nixos/modules/services/misc/preload.nix | 11 ++++------- 1 file changed, 4 insertions(+), 7 deletions(-) diff --git a/nixos/modules/services/misc/preload.nix b/nixos/modules/services/misc/preload.nix index d26e2c3d383e..4dadd0e26b16 100644 --- a/nixos/modules/services/misc/preload.nix +++ b/nixos/modules/services/misc/preload.nix @@ -1,25 +1,22 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.preload; in { meta = { maintainers = pkgs.preload.meta.maintainers; }; options.services.preload = { - enable = mkEnableOption "preload"; - package = mkPackageOption pkgs "preload" { }; + enable = lib.mkEnableOption "preload"; + package = lib.mkPackageOption pkgs "preload" { }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.preload = { description = "Loads data into ram during idle time of CPU."; wantedBy = [ "multi-user.target" ]; serviceConfig = { EnvironmentFile = "${cfg.package}/etc/conf.d/preload"; - ExecStart = "${getExe cfg.package} -l '' --foreground $PRELOAD_OPTS"; + ExecStart = "${lib.getExe cfg.package} -l '' --foreground $PRELOAD_OPTS"; Type = "simple"; # Only preload data during CPU idle time IOSchedulingClass = 3; From 247134aefb55f06ccd8b5ed191908c0dd6250470 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:42 +0200 Subject: [PATCH 068/166] nixos/services.prowlarr: remove `with lib;` --- nixos/modules/services/misc/prowlarr.nix | 15 ++++++--------- 1 file changed, 6 insertions(+), 9 deletions(-) diff --git a/nixos/modules/services/misc/prowlarr.nix b/nixos/modules/services/misc/prowlarr.nix index e37f0dc36d14..906f75516abd 100644 --- a/nixos/modules/services/misc/prowlarr.nix +++ b/nixos/modules/services/misc/prowlarr.nix @@ -1,7 +1,4 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.services.prowlarr; @@ -9,19 +6,19 @@ in { options = { services.prowlarr = { - enable = mkEnableOption "Prowlarr, an indexer manager/proxy for Torrent trackers and Usenet indexers"; + enable = lib.mkEnableOption "Prowlarr, an indexer manager/proxy for Torrent trackers and Usenet indexers"; - package = mkPackageOption pkgs "prowlarr" { }; + package = lib.mkPackageOption pkgs "prowlarr" { }; - openFirewall = mkOption { - type = types.bool; + openFirewall = lib.mkOption { + type = lib.types.bool; default = false; description = "Open ports in the firewall for the Prowlarr web interface."; }; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.prowlarr = { description = "Prowlarr"; after = [ "network.target" ]; @@ -37,7 +34,7 @@ in environment.HOME = "/var/empty"; }; - networking.firewall = mkIf cfg.openFirewall { + networking.firewall = lib.mkIf cfg.openFirewall { allowedTCPPorts = [ 9696 ]; }; }; From f5c2c7bbf2d99e3d68fb4e3a98f4fcd06736558e Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:43 +0200 Subject: [PATCH 069/166] nixos/services.pykms: remove `with lib;` --- nixos/modules/services/misc/pykms.nix | 34 +++++++++++++-------------- 1 file changed, 16 insertions(+), 18 deletions(-) diff --git a/nixos/modules/services/misc/pykms.nix b/nixos/modules/services/misc/pykms.nix index d1b209e38932..5bdb0bd52c0f 100644 --- a/nixos/modules/services/misc/pykms.nix +++ b/nixos/modules/services/misc/pykms.nix @@ -1,6 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; let cfg = config.services.pykms; libDir = "/var/lib/pykms"; @@ -10,56 +8,56 @@ in meta.maintainers = with lib.maintainers; [ peterhoeg ]; imports = [ - (mkRemovedOptionModule [ "services" "pykms" "verbose" ] "Use services.pykms.logLevel instead") + (lib.mkRemovedOptionModule [ "services" "pykms" "verbose" ] "Use services.pykms.logLevel instead") ]; options = { services.pykms = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = "Whether to enable the PyKMS service."; }; - listenAddress = mkOption { - type = types.str; + listenAddress = lib.mkOption { + type = lib.types.str; default = "0.0.0.0"; description = "The IP address on which to listen."; }; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 1688; description = "The port on which to listen."; }; - openFirewallPort = mkOption { - type = types.bool; + openFirewallPort = lib.mkOption { + type = lib.types.bool; default = false; description = "Whether the listening port should be opened automatically."; }; - memoryLimit = mkOption { - type = types.str; + memoryLimit = lib.mkOption { + type = lib.types.str; default = "64M"; description = "How much memory to use at most."; }; - logLevel = mkOption { - type = types.enum [ "CRITICAL" "ERROR" "WARNING" "INFO" "DEBUG" "MININFO" ]; + logLevel = lib.mkOption { + type = lib.types.enum [ "CRITICAL" "ERROR" "WARNING" "INFO" "DEBUG" "MININFO" ]; default = "INFO"; description = "How much to log"; }; - extraArgs = mkOption { - type = types.listOf types.str; + extraArgs = lib.mkOption { + type = lib.types.listOf lib.types.str; default = [ ]; description = "Additional arguments"; }; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { networking.firewall.allowedTCPPorts = lib.mkIf cfg.openFirewallPort [ cfg.port ]; systemd.services.pykms = { From 39d9937d053ee7867330d6cf7ddbf61e42869db2 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:43 +0200 Subject: [PATCH 070/166] nixos/services.radarr: remove `with lib;` --- nixos/modules/services/misc/radarr.nix | 31 ++++++++++++-------------- 1 file changed, 14 insertions(+), 17 deletions(-) diff --git a/nixos/modules/services/misc/radarr.nix b/nixos/modules/services/misc/radarr.nix index d9f78c4e8ee6..54c6e9577b31 100644 --- a/nixos/modules/services/misc/radarr.nix +++ b/nixos/modules/services/misc/radarr.nix @@ -1,7 +1,4 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.services.radarr; @@ -9,37 +6,37 @@ in { options = { services.radarr = { - enable = mkEnableOption "Radarr, a UsetNet/BitTorrent movie downloader"; + enable = lib.mkEnableOption "Radarr, a UsetNet/BitTorrent movie downloader"; - package = mkPackageOption pkgs "radarr" { }; + package = lib.mkPackageOption pkgs "radarr" { }; - dataDir = mkOption { - type = types.str; + dataDir = lib.mkOption { + type = lib.types.str; default = "/var/lib/radarr/.config/Radarr"; description = "The directory where Radarr stores its data files."; }; - openFirewall = mkOption { - type = types.bool; + openFirewall = lib.mkOption { + type = lib.types.bool; default = false; description = "Open ports in the firewall for the Radarr web interface."; }; - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; default = "radarr"; description = "User account under which Radarr runs."; }; - group = mkOption { - type = types.str; + group = lib.mkOption { + type = lib.types.str; default = "radarr"; description = "Group under which Radarr runs."; }; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.tmpfiles.settings."10-radarr".${cfg.dataDir}.d = { inherit (cfg) user group; mode = "0700"; @@ -59,11 +56,11 @@ in }; }; - networking.firewall = mkIf cfg.openFirewall { + networking.firewall = lib.mkIf cfg.openFirewall { allowedTCPPorts = [ 7878 ]; }; - users.users = mkIf (cfg.user == "radarr") { + users.users = lib.mkIf (cfg.user == "radarr") { radarr = { group = cfg.group; home = cfg.dataDir; @@ -71,7 +68,7 @@ in }; }; - users.groups = mkIf (cfg.group == "radarr") { + users.groups = lib.mkIf (cfg.group == "radarr") { radarr.gid = config.ids.gids.radarr; }; }; From ba6e7e10bb36eaffba616b3ff1213e4a17a905c5 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:44 +0200 Subject: [PATCH 071/166] nixos/services.readarr: remove `with lib;` --- nixos/modules/services/misc/readarr.nix | 31 +++++++++++-------------- 1 file changed, 14 insertions(+), 17 deletions(-) diff --git a/nixos/modules/services/misc/readarr.nix b/nixos/modules/services/misc/readarr.nix index b76a70859f75..15f1bde2cdfc 100644 --- a/nixos/modules/services/misc/readarr.nix +++ b/nixos/modules/services/misc/readarr.nix @@ -1,41 +1,38 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.services.readarr; in { options = { services.readarr = { - enable = mkEnableOption "Readarr, a Usenet/BitTorrent ebook downloader"; + enable = lib.mkEnableOption "Readarr, a Usenet/BitTorrent ebook downloader"; - dataDir = mkOption { - type = types.str; + dataDir = lib.mkOption { + type = lib.types.str; default = "/var/lib/readarr/"; description = "The directory where Readarr stores its data files."; }; - package = mkPackageOption pkgs "readarr" { }; + package = lib.mkPackageOption pkgs "readarr" { }; - openFirewall = mkOption { - type = types.bool; + openFirewall = lib.mkOption { + type = lib.types.bool; default = false; description = '' Open ports in the firewall for Readarr ''; }; - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; default = "readarr"; description = '' User account under which Readarr runs. ''; }; - group = mkOption { - type = types.str; + group = lib.mkOption { + type = lib.types.str; default = "readarr"; description = '' Group under which Readarr runs. @@ -44,7 +41,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.tmpfiles.settings."10-readarr".${cfg.dataDir}.d = { inherit (cfg) user group; mode = "0700"; @@ -64,11 +61,11 @@ in }; }; - networking.firewall = mkIf cfg.openFirewall { + networking.firewall = lib.mkIf cfg.openFirewall { allowedTCPPorts = [ 8787 ]; }; - users.users = mkIf (cfg.user == "readarr") { + users.users = lib.mkIf (cfg.user == "readarr") { readarr = { description = "Readarr service"; home = cfg.dataDir; @@ -77,7 +74,7 @@ in }; }; - users.groups = mkIf (cfg.group == "readarr") { + users.groups = lib.mkIf (cfg.group == "readarr") { readarr = { }; }; }; From 0280cad9996e9075641bedb74b215443628fad6c Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:44 +0200 Subject: [PATCH 072/166] nixos/services.rippleDataApi: remove `with lib;` --- .../modules/services/misc/ripple-data-api.nix | 79 +++++++++---------- 1 file changed, 38 insertions(+), 41 deletions(-) diff --git a/nixos/modules/services/misc/ripple-data-api.nix b/nixos/modules/services/misc/ripple-data-api.nix index a699ce95cf0e..e01e891c95a8 100644 --- a/nixos/modules/services/misc/ripple-data-api.nix +++ b/nixos/modules/services/misc/ripple-data-api.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.rippleDataApi; @@ -23,8 +20,8 @@ let db_config = builtins.toJSON { production = { - username = optional (cfg.couchdb.pass != "") cfg.couchdb.user; - password = optional (cfg.couchdb.pass != "") cfg.couchdb.pass; + username = lib.optional (cfg.couchdb.pass != "") cfg.couchdb.user; + password = lib.optional (cfg.couchdb.pass != "") cfg.couchdb.pass; host = cfg.couchdb.host; port = cfg.couchdb.port; database = cfg.couchdb.db; @@ -35,105 +32,105 @@ let in { options = { services.rippleDataApi = { - enable = mkEnableOption "ripple data api"; + enable = lib.mkEnableOption "ripple data api"; - port = mkOption { + port = lib.mkOption { description = "Ripple data api port"; default = 5993; - type = types.port; + type = lib.types.port; }; - importMode = mkOption { + importMode = lib.mkOption { description = "Ripple data api import mode."; default = "liveOnly"; - type = types.enum ["live" "liveOnly"]; + type = lib.types.enum ["live" "liveOnly"]; }; - minLedger = mkOption { + minLedger = lib.mkOption { description = "Ripple data api minimal ledger to fetch."; default = null; - type = types.nullOr types.int; + type = lib.types.nullOr lib.types.int; }; - maxLedger = mkOption { + maxLedger = lib.mkOption { description = "Ripple data api maximal ledger to fetch."; default = null; - type = types.nullOr types.int; + type = lib.types.nullOr lib.types.int; }; redis = { - enable = mkOption { + enable = lib.mkOption { description = "Whether to enable caching of ripple data to redis."; default = true; - type = types.bool; + type = lib.types.bool; }; - host = mkOption { + host = lib.mkOption { description = "Ripple data api redis host."; default = "localhost"; - type = types.str; + type = lib.types.str; }; - port = mkOption { + port = lib.mkOption { description = "Ripple data api redis port."; default = 5984; - type = types.port; + type = lib.types.port; }; }; couchdb = { - host = mkOption { + host = lib.mkOption { description = "Ripple data api couchdb host."; default = "localhost"; - type = types.str; + type = lib.types.str; }; - port = mkOption { + port = lib.mkOption { description = "Ripple data api couchdb port."; default = 5984; - type = types.port; + type = lib.types.port; }; - db = mkOption { + db = lib.mkOption { description = "Ripple data api couchdb database."; default = "rippled"; - type = types.str; + type = lib.types.str; }; - user = mkOption { + user = lib.mkOption { description = "Ripple data api couchdb username."; default = "rippled"; - type = types.str; + type = lib.types.str; }; - pass = mkOption { + pass = lib.mkOption { description = "Ripple data api couchdb password."; default = ""; - type = types.str; + type = lib.types.str; }; - create = mkOption { + create = lib.mkOption { description = "Whether to create couchdb database needed by ripple data api."; - type = types.bool; + type = lib.types.bool; default = true; }; }; - rippleds = mkOption { + rippleds = lib.mkOption { description = "List of rippleds to be used by ripple data api."; default = [ "http://s_east.ripple.com:51234" "http://s_west.ripple.com:51234" ]; - type = types.listOf types.str; + type = lib.types.listOf lib.types.str; }; }; }; - config = mkIf (cfg.enable) { - services.couchdb.enable = mkDefault true; - services.couchdb.bindAddress = mkDefault "0.0.0.0"; - services.redis.enable = mkDefault true; + config = lib.mkIf (cfg.enable) { + services.couchdb.enable = lib.mkDefault true; + services.couchdb.bindAddress = lib.mkDefault "0.0.0.0"; + services.redis.enable = lib.mkDefault true; systemd.services.ripple-data-api = { after = [ "couchdb.service" "redis.service" "ripple-data-api-importer.service" ]; @@ -176,9 +173,9 @@ in { User = "ripple-data-api"; }; - preStart = mkMerge [ - (mkIf (cfg.couchdb.create) '' - HOST="http://${optionalString (cfg.couchdb.pass != "") "${cfg.couchdb.user}:${cfg.couchdb.pass}@"}${cfg.couchdb.host}:${toString cfg.couchdb.port}" + preStart = lib.mkMerge [ + (lib.mkIf (cfg.couchdb.create) '' + HOST="http://${lib.optionalString (cfg.couchdb.pass != "") "${cfg.couchdb.user}:${cfg.couchdb.pass}@"}${cfg.couchdb.host}:${toString cfg.couchdb.port}" curl -X PUT $HOST/${cfg.couchdb.db} || true '') "${pkgs.ripple-data-api}/bin/update-views" From 724f15d7d8789f32db3cca985c554bf0fe655569 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:45 +0200 Subject: [PATCH 073/166] nixos/services.rkvm: remove `with lib;` --- nixos/modules/services/misc/rkvm.nix | 60 ++++++++++++++-------------- 1 file changed, 29 insertions(+), 31 deletions(-) diff --git a/nixos/modules/services/misc/rkvm.nix b/nixos/modules/services/misc/rkvm.nix index ac747253635e..805b2923bb0f 100644 --- a/nixos/modules/services/misc/rkvm.nix +++ b/nixos/modules/services/misc/rkvm.nix @@ -1,6 +1,4 @@ { options, config, pkgs, lib, ... }: - -with lib; let opt = options.services.rkvm; cfg = config.services.rkvm; @@ -10,35 +8,35 @@ in meta.maintainers = [ ]; options.services.rkvm = { - enable = mkOption { + enable = lib.mkOption { default = cfg.server.enable || cfg.client.enable; - defaultText = literalExpression "config.${opt.server.enable} || config.${opt.client.enable}"; - type = types.bool; + defaultText = lib.literalExpression "config.${opt.server.enable} || config.${opt.client.enable}"; + type = lib.types.bool; description = '' Whether to enable rkvm, a Virtual KVM switch for Linux machines. ''; }; - package = mkPackageOption pkgs "rkvm" { }; + package = lib.mkPackageOption pkgs "rkvm" { }; server = { - enable = mkEnableOption "the rkvm server daemon (input transmitter)"; + enable = lib.mkEnableOption "the rkvm server daemon (input transmitter)"; - settings = mkOption { - type = types.submodule + settings = lib.mkOption { + type = lib.types.submodule { freeformType = toml.type; options = { - listen = mkOption { - type = types.str; + listen = lib.mkOption { + type = lib.types.str; default = "0.0.0.0:5258"; description = '' An internet socket address to listen on, either IPv4 or IPv6. ''; }; - switch-keys = mkOption { - type = types.listOf types.str; + switch-keys = lib.mkOption { + type = lib.types.listOf lib.types.str; default = [ "left-alt" "left-ctrl" ]; description = '' A key list specifying a host switch combination. @@ -47,8 +45,8 @@ in ''; }; - certificate = mkOption { - type = types.path; + certificate = lib.mkOption { + type = lib.types.path; default = "/etc/rkvm/certificate.pem"; description = '' TLS certificate path. @@ -59,8 +57,8 @@ in ''; }; - key = mkOption { - type = types.path; + key = lib.mkOption { + type = lib.types.path; default = "/etc/rkvm/key.pem"; description = '' TLS key path. @@ -71,8 +69,8 @@ in ''; }; - password = mkOption { - type = types.str; + password = lib.mkOption { + type = lib.types.str; description = '' Shared secret token to authenticate the client. Make sure this matches your client's config. @@ -87,23 +85,23 @@ in }; client = { - enable = mkEnableOption "the rkvm client daemon (input receiver)"; + enable = lib.mkEnableOption "the rkvm client daemon (input receiver)"; - settings = mkOption { - type = types.submodule + settings = lib.mkOption { + type = lib.types.submodule { freeformType = toml.type; options = { - server = mkOption { - type = types.str; + server = lib.mkOption { + type = lib.types.str; example = "192.168.0.123:5258"; description = '' An RKVM server's internet socket address, either IPv4 or IPv6. ''; }; - certificate = mkOption { - type = types.path; + certificate = lib.mkOption { + type = lib.types.path; default = "/etc/rkvm/certificate.pem"; description = '' TLS ceritficate path. @@ -114,8 +112,8 @@ in ''; }; - password = mkOption { - type = types.str; + password = lib.mkOption { + type = lib.types.str; description = '' Shared secret token to authenticate the client. Make sure this matches your server's config. @@ -131,7 +129,7 @@ in }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = [ cfg.package ]; systemd.services = @@ -156,8 +154,8 @@ in }; in { - rkvm-server = mkIf cfg.server.enable (mkBase "server"); - rkvm-client = mkIf cfg.client.enable (mkBase "client"); + rkvm-server = lib.mkIf cfg.server.enable (mkBase "server"); + rkvm-client = lib.mkIf cfg.client.enable (mkBase "client"); }; }; From e3f2e1c9fb1f93357e25d1b23456bda51e1e4484 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:45 +0200 Subject: [PATCH 074/166] nixos/services.rmfakecloud: remove `with lib;` --- nixos/modules/services/misc/rmfakecloud.nix | 35 ++++++++++----------- 1 file changed, 16 insertions(+), 19 deletions(-) diff --git a/nixos/modules/services/misc/rmfakecloud.nix b/nixos/modules/services/misc/rmfakecloud.nix index d19a9969a3ff..b1f81c10b9a4 100644 --- a/nixos/modules/services/misc/rmfakecloud.nix +++ b/nixos/modules/services/misc/rmfakecloud.nix @@ -4,9 +4,6 @@ pkgs, ... }: - -with lib; - let cfg = config.services.rmfakecloud; serviceDataDir = "/var/lib/rmfakecloud"; @@ -15,28 +12,28 @@ in { options = { services.rmfakecloud = { - enable = mkEnableOption "rmfakecloud remarkable self-hosted cloud"; + enable = lib.mkEnableOption "rmfakecloud remarkable self-hosted cloud"; - package = mkPackageOption pkgs "rmfakecloud" { }; + package = lib.mkPackageOption pkgs "rmfakecloud" { }; - storageUrl = mkOption { - type = types.str; + storageUrl = lib.mkOption { + type = lib.types.str; example = "https://local.appspot.com"; description = '' URL used by the tablet to access the rmfakecloud service. ''; }; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 3000; description = '' Listening port number. ''; }; - logLevel = mkOption { - type = types.enum [ + logLevel = lib.mkOption { + type = lib.types.enum [ "info" "debug" "warn" @@ -48,8 +45,8 @@ in ''; }; - extraSettings = mkOption { - type = with types; attrsOf str; + extraSettings = lib.mkOption { + type = with lib.types; attrsOf str; default = { }; example = { DATADIR = "/custom/path/for/rmfakecloud/data"; @@ -63,8 +60,8 @@ in ''; }; - environmentFile = mkOption { - type = with types; nullOr path; + environmentFile = lib.mkOption { + type = with lib.types; nullOr path; default = null; example = "/etc/secrets/rmfakecloud.env"; description = '' @@ -78,7 +75,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.rmfakecloud = { description = "rmfakecloud remarkable self-hosted cloud"; @@ -113,9 +110,9 @@ in Type = "simple"; Restart = "always"; - EnvironmentFile = mkIf (cfg.environmentFile != null) cfg.environmentFile; + EnvironmentFile = lib.mkIf (cfg.environmentFile != null) cfg.environmentFile; - AmbientCapabilities = mkIf (cfg.port < 1024) [ "CAP_NET_BIND_SERVICE" ]; + AmbientCapabilities = lib.mkIf (cfg.port < 1024) [ "CAP_NET_BIND_SERVICE" ]; DynamicUser = true; PrivateDevices = true; @@ -148,5 +145,5 @@ in }; }; - meta.maintainers = with maintainers; [ pacien ]; + meta.maintainers = with lib.maintainers; [ pacien ]; } From 1d3ea1dbe548e00ec63156896c85a7b219fffaff Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:45 +0200 Subject: [PATCH 075/166] nixos/services.safeeyes: remove `with lib;` --- nixos/modules/services/misc/safeeyes.nix | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/nixos/modules/services/misc/safeeyes.nix b/nixos/modules/services/misc/safeeyes.nix index 38970fd77527..1d225e4b39d9 100644 --- a/nixos/modules/services/misc/safeeyes.nix +++ b/nixos/modules/services/misc/safeeyes.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.safeeyes; @@ -16,7 +13,7 @@ in services.safeeyes = { - enable = mkEnableOption "the safeeyes OSGi service"; + enable = lib.mkEnableOption "the safeeyes OSGi service"; }; @@ -24,7 +21,7 @@ in ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = [ pkgs.safeeyes ]; From 1bf69e64ec7f66a65fa4cc052e1aef76fe480686 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:46 +0200 Subject: [PATCH 076/166] nixos/services.sdrplayApi: remove `with lib;` --- nixos/modules/services/misc/sdrplay.nix | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/nixos/modules/services/misc/sdrplay.nix b/nixos/modules/services/misc/sdrplay.nix index d56b1e4124d6..83b709a340a8 100644 --- a/nixos/modules/services/misc/sdrplay.nix +++ b/nixos/modules/services/misc/sdrplay.nix @@ -1,8 +1,7 @@ { config, lib, pkgs, ... }: -with lib; { options.services.sdrplayApi = { - enable = mkOption { + enable = lib.mkOption { default = false; example = true; description = '' @@ -17,7 +16,7 @@ with lib; }; }; - config = mkIf config.services.sdrplayApi.enable { + config = lib.mkIf config.services.sdrplayApi.enable { systemd.services.sdrplayApi = { description = "SDRplay API Service"; after = [ "network.target" ]; From 1b4c241f80efea537e8f5dee19b59f4f17eeded1 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:46 +0200 Subject: [PATCH 077/166] nixos/services.serviio: remove `with lib;` --- nixos/modules/services/misc/serviio.nix | 13 +++++-------- 1 file changed, 5 insertions(+), 8 deletions(-) diff --git a/nixos/modules/services/misc/serviio.nix b/nixos/modules/services/misc/serviio.nix index a9449e54f5b0..60b6113c5e09 100644 --- a/nixos/modules/services/misc/serviio.nix +++ b/nixos/modules/services/misc/serviio.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.serviio; @@ -28,16 +25,16 @@ in { options = { services.serviio = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether to enable the Serviio Media Server. ''; }; - dataDir = mkOption { - type = types.path; + dataDir = lib.mkOption { + type = lib.types.path; default = "/var/lib/serviio"; description = '' The directory where serviio stores its state, data, etc. @@ -49,7 +46,7 @@ in { ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.serviio = { description = "Serviio Media Server"; after = [ "network.target" ]; From e593a4c094d5ddcd9e7bcd3b29d41a4d4a26f5e8 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:46 +0200 Subject: [PATCH 078/166] nixos/services.sickbeard: remove `with lib;` --- nixos/modules/services/misc/sickbeard.nix | 37 +++++++++++------------ 1 file changed, 17 insertions(+), 20 deletions(-) diff --git a/nixos/modules/services/misc/sickbeard.nix b/nixos/modules/services/misc/sickbeard.nix index 51179fdb14d3..237abf7185a3 100644 --- a/nixos/modules/services/misc/sickbeard.nix +++ b/nixos/modules/services/misc/sickbeard.nix @@ -1,7 +1,4 @@ { config, lib, options, pkgs, ... }: - -with lib; - let name = "sickbeard"; @@ -17,41 +14,41 @@ in options = { services.sickbeard = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = "Whether to enable the sickbeard server."; }; - package = mkPackageOption pkgs "sickbeard" { + package = lib.mkPackageOption pkgs "sickbeard" { example = "sickrage"; extraDescription = '' Enable `pkgs.sickrage` or `pkgs.sickgear` as an alternative to SickBeard ''; }; - dataDir = mkOption { - type = types.path; + dataDir = lib.mkOption { + type = lib.types.path; default = "/var/lib/${name}"; description = "Path where to store data files."; }; - configFile = mkOption { - type = types.path; + configFile = lib.mkOption { + type = lib.types.path; default = "${cfg.dataDir}/config.ini"; - defaultText = literalExpression ''"''${config.${opt.dataDir}}/config.ini"''; + defaultText = lib.literalExpression ''"''${config.${opt.dataDir}}/config.ini"''; description = "Path to config file."; }; - port = mkOption { - type = types.ints.u16; + port = lib.mkOption { + type = lib.types.ints.u16; default = 8081; description = "Port to bind to."; }; - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; default = name; description = "User to run the service as"; }; - group = mkOption { - type = types.str; + group = lib.mkOption { + type = lib.types.str; default = name; description = "Group to run the service as"; }; @@ -61,9 +58,9 @@ in ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { - users.users = optionalAttrs (cfg.user == name) { + users.users = lib.optionalAttrs (cfg.user == name) { ${name} = { uid = config.ids.uids.sickbeard; group = cfg.group; @@ -73,7 +70,7 @@ in }; }; - users.groups = optionalAttrs (cfg.group == name) { + users.groups = lib.optionalAttrs (cfg.group == name) { ${name}.gid = config.ids.gids.sickbeard; }; From 2a8d189e9b6efc849328c1e694a395514e0056ae Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:47 +0200 Subject: [PATCH 079/166] nixos/services.signald: remove `with lib;` --- nixos/modules/services/misc/signald.nix | 22 ++++++++++------------ 1 file changed, 10 insertions(+), 12 deletions(-) diff --git a/nixos/modules/services/misc/signald.nix b/nixos/modules/services/misc/signald.nix index 45cf1434882f..bd60c8b98947 100644 --- a/nixos/modules/services/misc/signald.nix +++ b/nixos/modules/services/misc/signald.nix @@ -1,6 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; let cfg = config.services.signald; dataDir = "/var/lib/signald"; @@ -8,36 +6,36 @@ let in { options.services.signald = { - enable = mkEnableOption "signald, the unofficial daemon for interacting with Signal"; + enable = lib.mkEnableOption "signald, the unofficial daemon for interacting with Signal"; - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; default = defaultUser; description = "User under which signald runs."; }; - group = mkOption { - type = types.str; + group = lib.mkOption { + type = lib.types.str; default = defaultUser; description = "Group under which signald runs."; }; - socketPath = mkOption { - type = types.str; + socketPath = lib.mkOption { + type = lib.types.str; default = "/run/signald/signald.sock"; description = "Path to the signald socket"; }; }; - config = mkIf cfg.enable { - users.users = optionalAttrs (cfg.user == defaultUser) { + config = lib.mkIf cfg.enable { + users.users = lib.optionalAttrs (cfg.user == defaultUser) { ${defaultUser} = { group = cfg.group; isSystemUser = true; }; }; - users.groups = optionalAttrs (cfg.group == defaultUser) { + users.groups = lib.optionalAttrs (cfg.group == defaultUser) { ${defaultUser} = { }; }; From 288a6271548e2334ff4e06f17f62278b7f7f7a2e Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:47 +0200 Subject: [PATCH 080/166] nixos/services.siproxd: remove `with lib;` --- nixos/modules/services/misc/siproxd.nix | 69 ++++++++++++------------- 1 file changed, 33 insertions(+), 36 deletions(-) diff --git a/nixos/modules/services/misc/siproxd.nix b/nixos/modules/services/misc/siproxd.nix index bedc91e3b43c..f941ded12395 100644 --- a/nixos/modules/services/misc/siproxd.nix +++ b/nixos/modules/services/misc/siproxd.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.siproxd; @@ -17,10 +14,10 @@ let rtp_port_high = ${toString cfg.rtpPortHigh} rtp_dscp = ${toString cfg.rtpDscp} sip_dscp = ${toString cfg.sipDscp} - ${optionalString (cfg.hostsAllowReg != []) "hosts_allow_reg = ${concatStringsSep "," cfg.hostsAllowReg}"} - ${optionalString (cfg.hostsAllowSip != []) "hosts_allow_sip = ${concatStringsSep "," cfg.hostsAllowSip}"} - ${optionalString (cfg.hostsDenySip != []) "hosts_deny_sip = ${concatStringsSep "," cfg.hostsDenySip}"} - ${optionalString (cfg.passwordFile != "") "proxy_auth_pwfile = ${cfg.passwordFile}"} + ${lib.optionalString (cfg.hostsAllowReg != []) "hosts_allow_reg = ${lib.concatStringsSep "," cfg.hostsAllowReg}"} + ${lib.optionalString (cfg.hostsAllowSip != []) "hosts_allow_sip = ${lib.concatStringsSep "," cfg.hostsAllowSip}"} + ${lib.optionalString (cfg.hostsDenySip != []) "hosts_deny_sip = ${lib.concatStringsSep "," cfg.hostsDenySip}"} + ${lib.optionalString (cfg.passwordFile != "") "proxy_auth_pwfile = ${cfg.passwordFile}"} ${cfg.extraConfig} ''; @@ -34,8 +31,8 @@ in services.siproxd = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether to enable the Siproxd SIP @@ -43,20 +40,20 @@ in ''; }; - ifInbound = mkOption { - type = types.str; + ifInbound = lib.mkOption { + type = lib.types.str; example = "eth0"; description = "Local network interface"; }; - ifOutbound = mkOption { - type = types.str; + ifOutbound = lib.mkOption { + type = lib.types.str; example = "ppp0"; description = "Public network interface"; }; - hostsAllowReg = mkOption { - type = types.listOf types.str; + hostsAllowReg = lib.mkOption { + type = lib.types.listOf lib.types.str; default = [ ]; example = [ "192.168.1.0/24" "192.168.2.0/24" ]; description = '' @@ -64,8 +61,8 @@ in ''; }; - hostsAllowSip = mkOption { - type = types.listOf types.str; + hostsAllowSip = lib.mkOption { + type = lib.types.listOf lib.types.str; default = [ ]; example = [ "123.45.0.0/16" "123.46.0.0/16" ]; description = '' @@ -73,8 +70,8 @@ in ''; }; - hostsDenySip = mkOption { - type = types.listOf types.str; + hostsDenySip = lib.mkOption { + type = lib.types.listOf lib.types.str; default = [ ]; example = [ "10.0.0.0/8" "11.0.0.0/8" ]; description = '' @@ -83,32 +80,32 @@ in ''; }; - sipListenPort = mkOption { - type = types.int; + sipListenPort = lib.mkOption { + type = lib.types.int; default = 5060; description = '' Port to listen for incoming SIP messages. ''; }; - rtpPortLow = mkOption { - type = types.int; + rtpPortLow = lib.mkOption { + type = lib.types.int; default = 7070; description = '' Bottom of UDP port range for incoming and outgoing RTP traffic ''; }; - rtpPortHigh = mkOption { - type = types.int; + rtpPortHigh = lib.mkOption { + type = lib.types.int; default = 7089; description = '' Top of UDP port range for incoming and outgoing RTP traffic ''; }; - rtpTimeout = mkOption { - type = types.int; + rtpTimeout = lib.mkOption { + type = lib.types.int; default = 300; description = '' Timeout for an RTP stream. If for the specified @@ -117,8 +114,8 @@ in ''; }; - rtpDscp = mkOption { - type = types.int; + rtpDscp = lib.mkOption { + type = lib.types.int; default = 46; description = '' DSCP (differentiated services) value to be assigned @@ -127,8 +124,8 @@ in ''; }; - sipDscp = mkOption { - type = types.int; + sipDscp = lib.mkOption { + type = lib.types.int; default = 0; description = '' DSCP (differentiated services) value to be assigned @@ -137,16 +134,16 @@ in ''; }; - passwordFile = mkOption { - type = types.str; + passwordFile = lib.mkOption { + type = lib.types.str; default = ""; description = '' Path to per-user password file. ''; }; - extraConfig = mkOption { - type = types.lines; + extraConfig = lib.mkOption { + type = lib.types.lines; default = ""; description = '' Extra configuration to add to siproxd configuration. @@ -159,7 +156,7 @@ in ##### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { users.users.siproxyd = { uid = config.ids.uids.siproxd; From b84a9d0112d86e5a7ea142ae5d642e585b58967d Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:47 +0200 Subject: [PATCH 081/166] nixos/services.soft-serve: remove `with lib;` --- nixos/modules/services/misc/soft-serve.nix | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-) diff --git a/nixos/modules/services/misc/soft-serve.nix b/nixos/modules/services/misc/soft-serve.nix index 1907d92adb85..9a3fb1af9b81 100644 --- a/nixos/modules/services/misc/soft-serve.nix +++ b/nixos/modules/services/misc/soft-serve.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.soft-serve; configFile = format.generate "config.yaml" cfg.settings; @@ -12,11 +9,11 @@ in { options = { services.soft-serve = { - enable = mkEnableOption "soft-serve"; + enable = lib.mkEnableOption "soft-serve"; - package = mkPackageOption pkgs "soft-serve" { }; + package = lib.mkPackageOption pkgs "soft-serve" { }; - settings = mkOption { + settings = lib.mkOption { type = format.type; default = { }; description = '' @@ -24,7 +21,7 @@ in See <${docUrl}>. ''; - example = literalExpression '' + example = lib.literalExpression '' { name = "dadada's repos"; log_format = "text"; @@ -41,7 +38,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.tmpfiles.rules = [ # The config file has to be inside the state dir @@ -61,7 +58,7 @@ in Type = "simple"; DynamicUser = true; Restart = "always"; - ExecStart = "${getExe cfg.package} serve"; + ExecStart = "${lib.getExe cfg.package} serve"; StateDirectory = "soft-serve"; WorkingDirectory = stateDir; RuntimeDirectory = "soft-serve"; @@ -95,5 +92,5 @@ in }; }; - meta.maintainers = [ maintainers.dadada ]; + meta.maintainers = [ lib.maintainers.dadada ]; } From 7abfa8873a9f8498f4e6a73593ae281b57950521 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:48 +0200 Subject: [PATCH 082/166] nixos/services.sonarr: remove `with lib;` --- nixos/modules/services/misc/sonarr.nix | 31 ++++++++++++-------------- 1 file changed, 14 insertions(+), 17 deletions(-) diff --git a/nixos/modules/services/misc/sonarr.nix b/nixos/modules/services/misc/sonarr.nix index 60e73198d60d..b147bf9e69f4 100644 --- a/nixos/modules/services/misc/sonarr.nix +++ b/nixos/modules/services/misc/sonarr.nix @@ -1,46 +1,43 @@ { config, pkgs, lib, utils, ... }: - -with lib; - let cfg = config.services.sonarr; in { options = { services.sonarr = { - enable = mkEnableOption "Sonarr"; + enable = lib.mkEnableOption "Sonarr"; - dataDir = mkOption { - type = types.str; + dataDir = lib.mkOption { + type = lib.types.str; default = "/var/lib/sonarr/.config/NzbDrone"; description = "The directory where Sonarr stores its data files."; }; - openFirewall = mkOption { - type = types.bool; + openFirewall = lib.mkOption { + type = lib.types.bool; default = false; description = '' Open ports in the firewall for the Sonarr web interface ''; }; - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; default = "sonarr"; description = "User account under which Sonaar runs."; }; - group = mkOption { - type = types.str; + group = lib.mkOption { + type = lib.types.str; default = "sonarr"; description = "Group under which Sonaar runs."; }; - package = mkPackageOption pkgs "sonarr" { }; + package = lib.mkPackageOption pkgs "sonarr" { }; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.tmpfiles.rules = [ "d '${cfg.dataDir}' 0700 ${cfg.user} ${cfg.group} - -" ]; @@ -63,11 +60,11 @@ in }; }; - networking.firewall = mkIf cfg.openFirewall { + networking.firewall = lib.mkIf cfg.openFirewall { allowedTCPPorts = [ 8989 ]; }; - users.users = mkIf (cfg.user == "sonarr") { + users.users = lib.mkIf (cfg.user == "sonarr") { sonarr = { group = cfg.group; home = cfg.dataDir; @@ -75,7 +72,7 @@ in }; }; - users.groups = mkIf (cfg.group == "sonarr") { + users.groups = lib.mkIf (cfg.group == "sonarr") { sonarr.gid = config.ids.gids.sonarr; }; }; From e4c0bdd97fe4d166db67ddd1631ddd5ddfa0222a Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:48 +0200 Subject: [PATCH 083/166] nixos/services.spice-vdagentd: remove `with lib;` --- nixos/modules/services/misc/spice-vdagentd.nix | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/nixos/modules/services/misc/spice-vdagentd.nix b/nixos/modules/services/misc/spice-vdagentd.nix index 2dd9fcf68ab0..762f9c95b615 100644 --- a/nixos/modules/services/misc/spice-vdagentd.nix +++ b/nixos/modules/services/misc/spice-vdagentd.nix @@ -1,17 +1,15 @@ { config, pkgs, lib, ... }: - -with lib; let cfg = config.services.spice-vdagentd; in { options = { services.spice-vdagentd = { - enable = mkEnableOption "Spice guest vdagent daemon"; + enable = lib.mkEnableOption "Spice guest vdagent daemon"; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = [ pkgs.spice-vdagent ]; From 4a435c16d2969036fd3de1e51194f64eb5c2501f Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:48 +0200 Subject: [PATCH 084/166] nixos/services.spice-webdavd: remove `with lib;` --- nixos/modules/services/misc/spice-webdavd.nix | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/nixos/modules/services/misc/spice-webdavd.nix b/nixos/modules/services/misc/spice-webdavd.nix index 9df0f7a420e7..6f12f4418aaa 100644 --- a/nixos/modules/services/misc/spice-webdavd.nix +++ b/nixos/modules/services/misc/spice-webdavd.nix @@ -1,19 +1,17 @@ { config, pkgs, lib, ... }: - -with lib; let cfg = config.services.spice-webdavd; in { options = { services.spice-webdavd = { - enable = mkEnableOption "the spice guest webdav proxy daemon"; + enable = lib.mkEnableOption "the spice guest webdav proxy daemon"; - package = mkPackageOption pkgs "phodav" { }; + package = lib.mkPackageOption pkgs "phodav" { }; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { # ensure the webdav fs this exposes can actually be mounted services.davfs2.enable = true; From 269e2407e919fd94101f9d5196ae4fc4f0618b61 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:49 +0200 Subject: [PATCH 085/166] nixos/services.sssd: remove `with lib;` --- nixos/modules/services/misc/sssd.nix | 29 ++++++++++++++-------------- 1 file changed, 14 insertions(+), 15 deletions(-) diff --git a/nixos/modules/services/misc/sssd.nix b/nixos/modules/services/misc/sssd.nix index f2798c1f30b4..6d6f855c57f1 100644 --- a/nixos/modules/services/misc/sssd.nix +++ b/nixos/modules/services/misc/sssd.nix @@ -1,5 +1,4 @@ { config, lib, pkgs, ... }: -with lib; let cfg = config.services.sssd; nscd = config.services.nscd; @@ -10,10 +9,10 @@ let in { options = { services.sssd = { - enable = mkEnableOption "the System Security Services Daemon"; + enable = lib.mkEnableOption "the System Security Services Daemon"; - config = mkOption { - type = types.lines; + config = lib.mkOption { + type = lib.types.lines; description = "Contents of {file}`sssd.conf`."; default = '' [sssd] @@ -34,8 +33,8 @@ in { ''; }; - sshAuthorizedKeysIntegration = mkOption { - type = types.bool; + sshAuthorizedKeysIntegration = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether to make sshd look up authorized keys from SSS. @@ -43,16 +42,16 @@ in { ''; }; - kcm = mkOption { - type = types.bool; + kcm = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether to use SSS as a Kerberos Cache Manager (KCM). Kerberos will be configured to cache credentials in SSS. ''; }; - environmentFile = mkOption { - type = types.nullOr types.path; + environmentFile = lib.mkOption { + type = lib.types.nullOr lib.types.path; default = null; description = '' Environment file as defined in {manpage}`systemd.exec(5)`. @@ -75,8 +74,8 @@ in { }; }; }; - config = mkMerge [ - (mkIf cfg.enable { + config = lib.mkMerge [ + (lib.mkIf cfg.enable { # For `sssctl` to work. environment.etc."sssd/sssd.conf".source = settingsFile; environment.etc."sssd/conf.d".source = "${dataDir}/conf.d"; @@ -126,7 +125,7 @@ in { services.dbus.packages = [ pkgs.sssd ]; }) - (mkIf cfg.kcm { + (lib.mkIf cfg.kcm { systemd.services.sssd-kcm = { description = "SSSD Kerberos Cache Manager"; requires = [ "sssd-kcm.socket" ]; @@ -148,7 +147,7 @@ in { security.krb5.settings.libdefaults.default_ccache_name = "KCM:"; }) - (mkIf cfg.sshAuthorizedKeysIntegration { + (lib.mkIf cfg.sshAuthorizedKeysIntegration { # Ugly: sshd refuses to start if a store path is given because /nix/store is group-writable. # So indirect by a symlink. environment.etc."ssh/authorized_keys_command" = { @@ -162,5 +161,5 @@ in { services.openssh.authorizedKeysCommandUser = "nobody"; })]; - meta.maintainers = with maintainers; [ bbigras ]; + meta.maintainers = with lib.maintainers; [ bbigras ]; } From 5adb3502aa519f0b2da3bcb8a844a2ad963855e6 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:49 +0200 Subject: [PATCH 086/166] nixos/services.subsonic: remove `with lib;` --- nixos/modules/services/misc/subsonic.nix | 49 +++++++++++------------- 1 file changed, 23 insertions(+), 26 deletions(-) diff --git a/nixos/modules/services/misc/subsonic.nix b/nixos/modules/services/misc/subsonic.nix index 2dda8970dd30..8d2ddf724f70 100644 --- a/nixos/modules/services/misc/subsonic.nix +++ b/nixos/modules/services/misc/subsonic.nix @@ -1,17 +1,14 @@ { config, lib, options, pkgs, ... }: - -with lib; - let cfg = config.services.subsonic; opt = options.services.subsonic; in { options = { services.subsonic = { - enable = mkEnableOption "Subsonic daemon"; + enable = lib.mkEnableOption "Subsonic daemon"; - home = mkOption { - type = types.path; + home = lib.mkOption { + type = lib.types.path; default = "/var/lib/subsonic"; description = '' The directory where Subsonic will create files. @@ -19,8 +16,8 @@ in { ''; }; - listenAddress = mkOption { - type = types.str; + listenAddress = lib.mkOption { + type = lib.types.str; default = "0.0.0.0"; description = '' The host name or IP address on which to bind Subsonic. @@ -30,8 +27,8 @@ in { ''; }; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 4040; description = '' The port on which Subsonic will listen for @@ -39,8 +36,8 @@ in { ''; }; - httpsPort = mkOption { - type = types.port; + httpsPort = lib.mkOption { + type = lib.types.port; default = 0; description = '' The port on which Subsonic will listen for @@ -48,8 +45,8 @@ in { ''; }; - contextPath = mkOption { - type = types.path; + contextPath = lib.mkOption { + type = lib.types.path; default = "/"; description = '' The context path, i.e., the last part of the Subsonic @@ -57,8 +54,8 @@ in { ''; }; - maxMemory = mkOption { - type = types.int; + maxMemory = lib.mkOption { + type = lib.types.int; default = 100; description = '' The memory limit (max Java heap size) in megabytes. @@ -66,8 +63,8 @@ in { ''; }; - defaultMusicFolder = mkOption { - type = types.path; + defaultMusicFolder = lib.mkOption { + type = lib.types.path; default = "/var/music"; description = '' Configure Subsonic to use this folder for music. This option @@ -75,8 +72,8 @@ in { ''; }; - defaultPodcastFolder = mkOption { - type = types.path; + defaultPodcastFolder = lib.mkOption { + type = lib.types.path; default = "/var/music/Podcast"; description = '' Configure Subsonic to use this folder for Podcasts. This option @@ -84,8 +81,8 @@ in { ''; }; - defaultPlaylistFolder = mkOption { - type = types.path; + defaultPlaylistFolder = lib.mkOption { + type = lib.types.path; default = "/var/playlists"; description = '' Configure Subsonic to use this folder for playlists. This option @@ -93,10 +90,10 @@ in { ''; }; - transcoders = mkOption { - type = types.listOf types.path; + transcoders = lib.mkOption { + type = lib.types.listOf lib.types.path; default = [ "${pkgs.ffmpeg.bin}/bin/ffmpeg" ]; - defaultText = literalExpression ''[ "''${pkgs.ffmpeg.bin}/bin/ffmpeg" ]''; + defaultText = lib.literalExpression ''[ "''${pkgs.ffmpeg.bin}/bin/ffmpeg" ]''; description = '' List of paths to transcoder executables that should be accessible from Subsonic. Symlinks will be created to each executable inside @@ -106,7 +103,7 @@ in { }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.subsonic = { description = "Personal media streamer"; after = [ "network.target" ]; From 07819ffd98dea66babe72bfd6ddf4411c5d0062f Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:49 +0200 Subject: [PATCH 087/166] nixos/services.sundtek: remove `with lib;` --- nixos/modules/services/misc/sundtek.nix | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/nixos/modules/services/misc/sundtek.nix b/nixos/modules/services/misc/sundtek.nix index e3234518c940..089d86cb5972 100644 --- a/nixos/modules/services/misc/sundtek.nix +++ b/nixos/modules/services/misc/sundtek.nix @@ -1,17 +1,14 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.sundtek; in { options.services.sundtek = { - enable = mkEnableOption "Sundtek driver"; + enable = lib.mkEnableOption "Sundtek driver"; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = [ pkgs.sundtek ]; From 165ad257f7c489a7d5e759d8e58c4369cac3b4cf Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:49 +0200 Subject: [PATCH 088/166] nixos/services.svnserve: remove `with lib;` --- nixos/modules/services/misc/svnserve.nix | 13 +++++-------- 1 file changed, 5 insertions(+), 8 deletions(-) diff --git a/nixos/modules/services/misc/svnserve.nix b/nixos/modules/services/misc/svnserve.nix index 5fa262ca3b94..8e0aee51754c 100644 --- a/nixos/modules/services/misc/svnserve.nix +++ b/nixos/modules/services/misc/svnserve.nix @@ -1,8 +1,5 @@ # SVN server { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.svnserve; @@ -17,14 +14,14 @@ in services.svnserve = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = "Whether to enable svnserve to serve Subversion repositories through the SVN protocol."; }; - svnBaseDir = mkOption { - type = types.str; + svnBaseDir = lib.mkOption { + type = lib.types.str; default = "/repos"; description = "Base directory from which Subversion repositories are accessed."; }; @@ -35,7 +32,7 @@ in ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.svnserve = { after = [ "network.target" ]; wantedBy = [ "multi-user.target" ]; From 334d6eb4920e94ee9c649a2721ec1b986aaecc96 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:50 +0200 Subject: [PATCH 089/166] nixos/services.synergy: remove `with lib;` --- nixos/modules/services/misc/synergy.nix | 57 ++++++++++++------------- 1 file changed, 27 insertions(+), 30 deletions(-) diff --git a/nixos/modules/services/misc/synergy.nix b/nixos/modules/services/misc/synergy.nix index fb664fc071d1..495f29ba1f91 100644 --- a/nixos/modules/services/misc/synergy.nix +++ b/nixos/modules/services/misc/synergy.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfgC = config.services.synergy.client; @@ -19,60 +16,60 @@ in # !!! All these option descriptions needs to be cleaned up. client = { - enable = mkEnableOption "the Synergy client (receive keyboard and mouse events from a Synergy server)"; + enable = lib.mkEnableOption "the Synergy client (receive keyboard and mouse events from a Synergy server)"; - screenName = mkOption { + screenName = lib.mkOption { default = ""; - type = types.str; + type = lib.types.str; description = '' Use the given name instead of the hostname to identify ourselves to the server. ''; }; - serverAddress = mkOption { - type = types.str; + serverAddress = lib.mkOption { + type = lib.types.str; description = '' The server address is of the form: [hostname][:port]. The hostname must be the address or hostname of the server. The port overrides the default port, 24800. ''; }; - autoStart = mkOption { + autoStart = lib.mkOption { default = true; - type = types.bool; + type = lib.types.bool; description = "Whether the Synergy client should be started automatically."; }; }; server = { - enable = mkEnableOption "the Synergy server (send keyboard and mouse events)"; + enable = lib.mkEnableOption "the Synergy server (send keyboard and mouse events)"; - configFile = mkOption { - type = types.path; + configFile = lib.mkOption { + type = lib.types.path; default = "/etc/synergy-server.conf"; description = "The Synergy server configuration file."; }; - screenName = mkOption { - type = types.str; + screenName = lib.mkOption { + type = lib.types.str; default = ""; description = '' Use the given name instead of the hostname to identify this screen in the configuration. ''; }; - address = mkOption { - type = types.str; + address = lib.mkOption { + type = lib.types.str; default = ""; description = "Address on which to listen for clients."; }; - autoStart = mkOption { + autoStart = lib.mkOption { default = true; - type = types.bool; + type = lib.types.bool; description = "Whether the Synergy server should be started automatically."; }; tls = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether TLS encryption should be used. @@ -83,8 +80,8 @@ in ''; }; - cert = mkOption { - type = types.nullOr types.str; + cert = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; example = "~/.synergy/SSL/Synergy.pem"; description = "The TLS certificate to use for encryption."; @@ -98,24 +95,24 @@ in ###### implementation - config = mkMerge [ - (mkIf cfgC.enable { + config = lib.mkMerge [ + (lib.mkIf cfgC.enable { systemd.user.services.synergy-client = { after = [ "network.target" "graphical-session.target" ]; description = "Synergy client"; - wantedBy = optional cfgC.autoStart "graphical-session.target"; + wantedBy = lib.optional cfgC.autoStart "graphical-session.target"; path = [ pkgs.synergy ]; - serviceConfig.ExecStart = ''${pkgs.synergy}/bin/synergyc -f ${optionalString (cfgC.screenName != "") "-n ${cfgC.screenName}"} ${cfgC.serverAddress}''; + serviceConfig.ExecStart = ''${pkgs.synergy}/bin/synergyc -f ${lib.optionalString (cfgC.screenName != "") "-n ${cfgC.screenName}"} ${cfgC.serverAddress}''; serviceConfig.Restart = "on-failure"; }; }) - (mkIf cfgS.enable { + (lib.mkIf cfgS.enable { systemd.user.services.synergy-server = { after = [ "network.target" "graphical-session.target" ]; description = "Synergy server"; - wantedBy = optional cfgS.autoStart "graphical-session.target"; + wantedBy = lib.optional cfgS.autoStart "graphical-session.target"; path = [ pkgs.synergy ]; - serviceConfig.ExecStart = ''${pkgs.synergy}/bin/synergys -c ${cfgS.configFile} -f${optionalString (cfgS.address != "") " -a ${cfgS.address}"}${optionalString (cfgS.screenName != "") " -n ${cfgS.screenName}"}${optionalString cfgS.tls.enable " --enable-crypto"}${optionalString (cfgS.tls.cert != null) (" --tls-cert ${cfgS.tls.cert}")}''; + serviceConfig.ExecStart = ''${pkgs.synergy}/bin/synergys -c ${cfgS.configFile} -f${lib.optionalString (cfgS.address != "") " -a ${cfgS.address}"}${lib.optionalString (cfgS.screenName != "") " -n ${cfgS.screenName}"}${lib.optionalString cfgS.tls.enable " --enable-crypto"}${lib.optionalString (cfgS.tls.cert != null) (" --tls-cert ${cfgS.tls.cert}")}''; serviceConfig.Restart = "on-failure"; }; }) From cc25de02a5dac1711a1eb79b82d12cc050ffa6a2 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:50 +0200 Subject: [PATCH 090/166] nixos/services.tandoor-recipes: remove `with lib;` --- .../modules/services/misc/tandoor-recipes.nix | 24 +++++++++---------- 1 file changed, 11 insertions(+), 13 deletions(-) diff --git a/nixos/modules/services/misc/tandoor-recipes.nix b/nixos/modules/services/misc/tandoor-recipes.nix index f8a85e0ac221..dd458f72565b 100644 --- a/nixos/modules/services/misc/tandoor-recipes.nix +++ b/nixos/modules/services/misc/tandoor-recipes.nix @@ -1,6 +1,4 @@ { config, pkgs, lib, ... }: - -with lib; let cfg = config.services.tandoor-recipes; pkg = cfg.package; @@ -11,7 +9,7 @@ let DEBUG = "0"; DEBUG_TOOLBAR = "0"; MEDIA_ROOT = "/var/lib/tandoor-recipes"; - } // optionalAttrs (config.time.timeZone != null) { + } // lib.optionalAttrs (config.time.timeZone != null) { TZ = config.time.timeZone; } // ( lib.mapAttrs (_: toString) cfg.extraConfig @@ -27,10 +25,10 @@ let ''; in { - meta.maintainers = with maintainers; [ ambroisie ]; + meta.maintainers = with lib.maintainers; [ ambroisie ]; options.services.tandoor-recipes = { - enable = mkOption { + enable = lib.mkOption { type = lib.types.bool; default = false; description = '' @@ -45,20 +43,20 @@ in ''; }; - address = mkOption { - type = types.str; + address = lib.mkOption { + type = lib.types.str; default = "localhost"; description = "Web interface address."; }; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 8080; description = "Web interface port."; }; - extraConfig = mkOption { - type = types.attrs; + extraConfig = lib.mkOption { + type = lib.types.attrs; default = { }; description = '' Extra tandoor recipes config options. @@ -71,10 +69,10 @@ in }; }; - package = mkPackageOption pkgs "tandoor-recipes" { }; + package = lib.mkPackageOption pkgs "tandoor-recipes" { }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.tandoor-recipes = { description = "Tandoor Recipes server"; From 2ecc659ae8b80e1c3a4f8ffd92f332e23a51e71f Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:51 +0200 Subject: [PATCH 091/166] nixos/services.tautulli: remove `with lib;` --- nixos/modules/services/misc/tautulli.nix | 39 +++++++++++------------- 1 file changed, 18 insertions(+), 21 deletions(-) diff --git a/nixos/modules/services/misc/tautulli.nix b/nixos/modules/services/misc/tautulli.nix index 6afdbd212aa8..467a632c7280 100644 --- a/nixos/modules/services/misc/tautulli.nix +++ b/nixos/modules/services/misc/tautulli.nix @@ -1,60 +1,57 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.services.tautulli; in { imports = [ - (mkRenamedOptionModule [ "services" "plexpy" ] [ "services" "tautulli" ]) + (lib.mkRenamedOptionModule [ "services" "plexpy" ] [ "services" "tautulli" ]) ]; options = { services.tautulli = { - enable = mkEnableOption "Tautulli Plex Monitor"; + enable = lib.mkEnableOption "Tautulli Plex Monitor"; - dataDir = mkOption { - type = types.str; + dataDir = lib.mkOption { + type = lib.types.str; default = "/var/lib/plexpy"; description = "The directory where Tautulli stores its data files."; }; - configFile = mkOption { - type = types.str; + configFile = lib.mkOption { + type = lib.types.str; default = "/var/lib/plexpy/config.ini"; description = "The location of Tautulli's config file."; }; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 8181; description = "TCP port where Tautulli listens."; }; - openFirewall = mkOption { - type = types.bool; + openFirewall = lib.mkOption { + type = lib.types.bool; default = false; description = "Open ports in the firewall for Tautulli."; }; - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; default = "plexpy"; description = "User account under which Tautulli runs."; }; - group = mkOption { - type = types.str; + group = lib.mkOption { + type = lib.types.str; default = "nogroup"; description = "Group under which Tautulli runs."; }; - package = mkPackageOption pkgs "tautulli" { }; + package = lib.mkPackageOption pkgs "tautulli" { }; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.tmpfiles.rules = [ "d '${cfg.dataDir}' - ${cfg.user} ${cfg.group} - -" ]; @@ -73,9 +70,9 @@ in }; }; - networking.firewall.allowedTCPPorts = mkIf cfg.openFirewall [ cfg.port ]; + networking.firewall.allowedTCPPorts = lib.mkIf cfg.openFirewall [ cfg.port ]; - users.users = mkIf (cfg.user == "plexpy") { + users.users = lib.mkIf (cfg.user == "plexpy") { plexpy = { group = cfg.group; uid = config.ids.uids.plexpy; }; }; }; From d279b64dc1fb77cd06917533bafda23028741bd1 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:51 +0200 Subject: [PATCH 092/166] nixos/services.tiddlywiki: remove `with lib;` --- nixos/modules/services/misc/tiddlywiki.nix | 13 +++++-------- 1 file changed, 5 insertions(+), 8 deletions(-) diff --git a/nixos/modules/services/misc/tiddlywiki.nix b/nixos/modules/services/misc/tiddlywiki.nix index 7ae657dd862d..4cff412132d1 100644 --- a/nixos/modules/services/misc/tiddlywiki.nix +++ b/nixos/modules/services/misc/tiddlywiki.nix @@ -1,11 +1,8 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.tiddlywiki; - listenParams = concatStrings (mapAttrsToList (n: v: " '${n}=${toString v}' ") cfg.listenOptions); + listenParams = lib.concatStrings (lib.mapAttrsToList (n: v: " '${n}=${toString v}' ") cfg.listenOptions); exe = "${pkgs.nodePackages.tiddlywiki}/lib/node_modules/.bin/tiddlywiki"; name = "tiddlywiki"; dataDir = "/var/lib/" + name; @@ -14,10 +11,10 @@ in { options.services.tiddlywiki = { - enable = mkEnableOption "TiddlyWiki nodejs server"; + enable = lib.mkEnableOption "TiddlyWiki nodejs server"; - listenOptions = mkOption { - type = types.attrs; + listenOptions = lib.mkOption { + type = lib.types.attrs; default = {}; example = { credentials = "../credentials.csv"; @@ -32,7 +29,7 @@ in { }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd = { services.tiddlywiki = { description = "TiddlyWiki nodejs server"; From 11904bba7374ce1fa8ecd3d5b62210a022e590cc Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:51 +0200 Subject: [PATCH 093/166] nixos/services.tp-auto-kbbl: remove `with lib;` --- nixos/modules/services/misc/tp-auto-kbbl.nix | 21 +++++++++----------- 1 file changed, 9 insertions(+), 12 deletions(-) diff --git a/nixos/modules/services/misc/tp-auto-kbbl.nix b/nixos/modules/services/misc/tp-auto-kbbl.nix index 4ea356a133d8..fe0192116982 100644 --- a/nixos/modules/services/misc/tp-auto-kbbl.nix +++ b/nixos/modules/services/misc/tp-auto-kbbl.nix @@ -1,28 +1,25 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.tp-auto-kbbl; in { - meta.maintainers = with maintainers; [ sebtm ]; + meta.maintainers = with lib.maintainers; [ sebtm ]; options = { services.tp-auto-kbbl = { - enable = mkEnableOption "auto toggle keyboard back-lighting on Thinkpads (and maybe other laptops) for Linux"; + enable = lib.mkEnableOption "auto toggle keyboard back-lighting on Thinkpads (and maybe other laptops) for Linux"; - package = mkPackageOption pkgs "tp-auto-kbbl" { }; + package = lib.mkPackageOption pkgs "tp-auto-kbbl" { }; - arguments = mkOption { - type = types.listOf types.str; + arguments = lib.mkOption { + type = lib.types.listOf lib.types.str; default = [ ]; description = '' List of arguments appended to `./tp-auto-kbbl --device [device] [arguments]` ''; }; - device = mkOption { - type = types.str; + device = lib.mkOption { + type = lib.types.str; default = "/dev/input/event0"; description = "Device watched for activities."; }; @@ -30,12 +27,12 @@ in { }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = [ cfg.package ]; systemd.services.tp-auto-kbbl = { serviceConfig = { - ExecStart = concatStringsSep " " + ExecStart = lib.concatStringsSep " " ([ "${cfg.package}/bin/tp-auto-kbbl" "--device ${cfg.device}" ] ++ cfg.arguments); Restart = "always"; Type = "simple"; From f89578e7977fc41c30061faf31fe641cae31129e Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:51 +0200 Subject: [PATCH 094/166] nixos/programs.tuxclocker: remove `with lib;` --- nixos/modules/services/misc/tuxclocker.nix | 21 +++++++++------------ 1 file changed, 9 insertions(+), 12 deletions(-) diff --git a/nixos/modules/services/misc/tuxclocker.nix b/nixos/modules/services/misc/tuxclocker.nix index 4c2f9e39bcfc..ccbd4c6980e0 100644 --- a/nixos/modules/services/misc/tuxclocker.nix +++ b/nixos/modules/services/misc/tuxclocker.nix @@ -1,23 +1,20 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.programs.tuxclocker; in { options.programs.tuxclocker = { - enable = mkEnableOption '' + enable = lib.mkEnableOption '' TuxClocker, a hardware control and monitoring program ''; - enableAMD = mkEnableOption '' + enableAMD = lib.mkEnableOption '' AMD GPU controls. Sets the `amdgpu.ppfeaturemask` kernel parameter to 0xfffd7fff to enable all TuxClocker controls ''; - enabledNVIDIADevices = mkOption { - type = types.listOf types.int; + enabledNVIDIADevices = lib.mkOption { + type = lib.types.listOf lib.types.int; default = [ ]; example = [ 0 1 ]; description = '' @@ -26,8 +23,8 @@ in ''; }; - useUnfree = mkOption { - type = types.bool; + useUnfree = lib.mkOption { + type = lib.types.bool; default = false; example = true; description = '' @@ -40,7 +37,7 @@ in config = let package = if cfg.useUnfree then pkgs.tuxclocker else pkgs.tuxclocker-without-unfree; in - mkIf cfg.enable { + lib.mkIf cfg.enable { environment.systemPackages = [ package ]; @@ -62,10 +59,10 @@ in EndSection ''); in - concatStrings (map configSection cfg.enabledNVIDIADevices); + lib.concatStrings (map configSection cfg.enabledNVIDIADevices); # https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/drivers/gpu/drm/amd/include/amd_shared.h#n207 # Enable everything modifiable in TuxClocker - boot.kernelParams = mkIf cfg.enableAMD [ "amdgpu.ppfeaturemask=0xfffd7fff" ]; + boot.kernelParams = lib.mkIf cfg.enableAMD [ "amdgpu.ppfeaturemask=0xfffd7fff" ]; }; } From b04e01279b06da3dc1ed493c128a7d3620371a2b Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:52 +0200 Subject: [PATCH 095/166] nixos/services.tzupdate: remove `with lib;` --- nixos/modules/services/misc/tzupdate.nix | 9 +++------ 1 file changed, 3 insertions(+), 6 deletions(-) diff --git a/nixos/modules/services/misc/tzupdate.nix b/nixos/modules/services/misc/tzupdate.nix index 9e979bb47675..17868e1c1171 100644 --- a/nixos/modules/services/misc/tzupdate.nix +++ b/nixos/modules/services/misc/tzupdate.nix @@ -1,13 +1,10 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.tzupdate; in { options.services.tzupdate = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = '' Enable the tzupdate timezone updating service. This provides @@ -17,7 +14,7 @@ in { }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { # We need to have imperative time zone management for this to work. # This will give users an error if they have set an explicit time # zone, which is better than silently overriding it. From 43e70943dab80fcbbd8041c8d976a471180f4c2e Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:52 +0200 Subject: [PATCH 096/166] nixos/services.uhub: remove `with lib;` --- nixos/modules/services/misc/uhub.nix | 25 +++++++++++-------------- 1 file changed, 11 insertions(+), 14 deletions(-) diff --git a/nixos/modules/services/misc/uhub.nix b/nixos/modules/services/misc/uhub.nix index 99774fbb920a..58bf6a2c2ed7 100644 --- a/nixos/modules/services/misc/uhub.nix +++ b/nixos/modules/services/misc/uhub.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let settingsFormat = { type = with lib.types; attrsOf (oneOf [ bool int str ]); @@ -13,21 +10,21 @@ let in { options = { - services.uhub = mkOption { + services.uhub = lib.mkOption { default = { }; description = "Uhub ADC hub instances"; - type = types.attrsOf (types.submodule { + type = lib.types.attrsOf (lib.types.submodule { options = { - enable = mkEnableOption "hub instance" // { default = true; }; + enable = lib.mkEnableOption "hub instance" // { default = true; }; - enableTLS = mkOption { - type = types.bool; + enableTLS = lib.mkOption { + type = lib.types.bool; default = false; description = "Whether to enable TLS support."; }; - settings = mkOption { + settings = lib.mkOption { inherit (settingsFormat) type; description = '' Configuration of uhub. @@ -43,18 +40,18 @@ in { }; }; - plugins = mkOption { + plugins = lib.mkOption { description = "Uhub plugin configuration."; - type = with types; + type = with lib.types; listOf (submodule { options = { - plugin = mkOption { + plugin = lib.mkOption { type = path; - example = literalExpression + example = lib.literalExpression "$${pkgs.uhub}/plugins/mod_auth_sqlite.so"; description = "Path to plugin file."; }; - settings = mkOption { + settings = lib.mkOption { description = "Settings specific to this plugin."; type = with types; attrsOf str; example = { file = "/etc/uhub/users.db"; }; From fe175fe57571d1cf9202e792286495803e0fb127 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:52 +0200 Subject: [PATCH 097/166] nixos/services.weechat: remove `with lib;` --- nixos/modules/services/misc/weechat.nix | 23 ++++++++++------------- 1 file changed, 10 insertions(+), 13 deletions(-) diff --git a/nixos/modules/services/misc/weechat.nix b/nixos/modules/services/misc/weechat.nix index 6f6c78b1c9dc..45180e2bbd5f 100644 --- a/nixos/modules/services/misc/weechat.nix +++ b/nixos/modules/services/misc/weechat.nix @@ -1,34 +1,31 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.weechat; in { options.services.weechat = { - enable = mkEnableOption "weechat"; - root = mkOption { + enable = lib.mkEnableOption "weechat"; + root = lib.mkOption { description = "Weechat state directory."; - type = types.str; + type = lib.types.str; default = "/var/lib/weechat"; }; - sessionName = mkOption { + sessionName = lib.mkOption { description = "Name of the `screen` session for weechat."; default = "weechat-screen"; - type = types.str; + type = lib.types.str; }; - binary = mkOption { - type = types.path; + binary = lib.mkOption { + type = lib.types.path; description = "Binary to execute."; default = "${pkgs.weechat}/bin/weechat"; - defaultText = literalExpression ''"''${pkgs.weechat}/bin/weechat"''; - example = literalExpression ''"''${pkgs.weechat}/bin/weechat-headless"''; + defaultText = lib.literalExpression ''"''${pkgs.weechat}/bin/weechat"''; + example = lib.literalExpression ''"''${pkgs.weechat}/bin/weechat-headless"''; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { users = { groups.weechat = {}; users.weechat = { From f8b0d3a756825f8c19bfc691fe8f642765fbab90 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:53 +0200 Subject: [PATCH 098/166] nixos/services.xmrig: remove `with lib;` --- nixos/modules/services/misc/xmrig.nix | 16 +++++----------- 1 file changed, 5 insertions(+), 11 deletions(-) diff --git a/nixos/modules/services/misc/xmrig.nix b/nixos/modules/services/misc/xmrig.nix index d4e1be779972..4317f197d008 100644 --- a/nixos/modules/services/misc/xmrig.nix +++ b/nixos/modules/services/misc/xmrig.nix @@ -1,28 +1,22 @@ { config, pkgs, lib, ... }: - - let cfg = config.services.xmrig; - json = pkgs.formats.json { }; configFile = json.generate "config.json" cfg.settings; in - -with lib; - { options = { services.xmrig = { - enable = mkEnableOption "XMRig Mining Software"; + enable = lib.mkEnableOption "XMRig Mining Software"; - package = mkPackageOption pkgs "xmrig" { + package = lib.mkPackageOption pkgs "xmrig" { example = "xmrig-mo"; }; - settings = mkOption { + settings = lib.mkOption { default = { }; type = json.type; - example = literalExpression '' + example = lib.literalExpression '' { autosave = true; cpu = true; @@ -47,7 +41,7 @@ with lib; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { hardware.cpu.x86.msr.enable = true; systemd.services.xmrig = { From 59a4e8349e6e34da2246a30707a78474671771b3 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:53 +0200 Subject: [PATCH 099/166] nixos/services.zookeeper: remove `with lib;` --- nixos/modules/services/misc/zookeeper.nix | 57 +++++++++++------------ 1 file changed, 27 insertions(+), 30 deletions(-) diff --git a/nixos/modules/services/misc/zookeeper.nix b/nixos/modules/services/misc/zookeeper.nix index 3861a3cd2f4d..fc06d56b0d5a 100644 --- a/nixos/modules/services/misc/zookeeper.nix +++ b/nixos/modules/services/misc/zookeeper.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.zookeeper; @@ -24,31 +21,31 @@ let in { options.services.zookeeper = { - enable = mkEnableOption "Zookeeper"; + enable = lib.mkEnableOption "Zookeeper"; - port = mkOption { + port = lib.mkOption { description = "Zookeeper Client port."; default = 2181; - type = types.port; + type = lib.types.port; }; - id = mkOption { + id = lib.mkOption { description = "Zookeeper ID."; default = 0; - type = types.int; + type = lib.types.int; }; - purgeInterval = mkOption { + purgeInterval = lib.mkOption { description = '' The time interval in hours for which the purge task has to be triggered. Set to a positive integer (1 and above) to enable the auto purging. ''; default = 1; - type = types.int; + type = lib.types.int; }; - extraConf = mkOption { + extraConf = lib.mkOption { description = "Extra configuration for Zookeeper."; - type = types.lines; + type = lib.types.lines; default = '' initLimit=5 syncLimit=2 @@ -56,10 +53,10 @@ in { ''; }; - servers = mkOption { + servers = lib.mkOption { description = "All Zookeeper Servers."; default = ""; - type = types.lines; + type = lib.types.lines; example = '' server.0=host0:2888:3888 server.1=host1:2888:3888 @@ -67,7 +64,7 @@ in { ''; }; - logging = mkOption { + logging = lib.mkOption { description = "Zookeeper logging configuration."; default = '' zookeeper.root.logger=INFO, CONSOLE @@ -77,45 +74,45 @@ in { log4j.appender.CONSOLE.layout=org.apache.log4j.PatternLayout log4j.appender.CONSOLE.layout.ConversionPattern=[myid:%X{myid}] - %-5p [%t:%C{1}@%L] - %m%n ''; - type = types.lines; + type = lib.types.lines; }; - dataDir = mkOption { - type = types.path; + dataDir = lib.mkOption { + type = lib.types.path; default = "/var/lib/zookeeper"; description = '' Data directory for Zookeeper ''; }; - extraCmdLineOptions = mkOption { + extraCmdLineOptions = lib.mkOption { description = "Extra command line options for the Zookeeper launcher."; default = [ "-Dcom.sun.management.jmxremote" "-Dcom.sun.management.jmxremote.local.only=true" ]; - type = types.listOf types.str; + type = lib.types.listOf lib.types.str; example = [ "-Djava.net.preferIPv4Stack=true" "-Dcom.sun.management.jmxremote" "-Dcom.sun.management.jmxremote.local.only=true" ]; }; - preferIPv4 = mkOption { - type = types.bool; + preferIPv4 = lib.mkOption { + type = lib.types.bool; default = true; description = '' Add the -Djava.net.preferIPv4Stack=true flag to the Zookeeper server. ''; }; - package = mkPackageOption pkgs "zookeeper" { }; + package = lib.mkPackageOption pkgs "zookeeper" { }; - jre = mkOption { + jre = lib.mkOption { description = "The JRE with which to run Zookeeper"; default = cfg.package.jre; - defaultText = literalExpression "pkgs.zookeeper.jre"; - example = literalExpression "pkgs.jre"; - type = types.package; + defaultText = lib.literalExpression "pkgs.zookeeper.jre"; + example = lib.literalExpression "pkgs.jre"; + type = lib.types.package; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = [cfg.package]; systemd.tmpfiles.rules = [ @@ -131,9 +128,9 @@ in { ExecStart = '' ${cfg.jre}/bin/java \ -cp "${cfg.package}/lib/*:${configDir}" \ - ${escapeShellArgs cfg.extraCmdLineOptions} \ + ${lib.escapeShellArgs cfg.extraCmdLineOptions} \ -Dzookeeper.datadir.autocreate=false \ - ${optionalString cfg.preferIPv4 "-Djava.net.preferIPv4Stack=true"} \ + ${lib.optionalString cfg.preferIPv4 "-Djava.net.preferIPv4Stack=true"} \ org.apache.zookeeper.server.quorum.QuorumPeerMain \ ${configDir}/zoo.cfg ''; From 44990e93c30691afa284fd4117dde3d9d882239a Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:53 +0200 Subject: [PATCH 100/166] nixos/services.alerta: remove `with lib;` --- nixos/modules/services/monitoring/alerta.nix | 45 +++++++++----------- 1 file changed, 21 insertions(+), 24 deletions(-) diff --git a/nixos/modules/services/monitoring/alerta.nix b/nixos/modules/services/monitoring/alerta.nix index 32c71e730102..54aff7d6a92c 100644 --- a/nixos/modules/services/monitoring/alerta.nix +++ b/nixos/modules/services/monitoring/alerta.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.alerta; @@ -12,7 +9,7 @@ let DATABASE_NAME = '${cfg.databaseName}' LOG_FILE = '${cfg.logDir}/alertad.log' LOG_FORMAT = '%(asctime)s - %(name)s - %(levelname)s - %(message)s' - CORS_ORIGINS = [ ${concatMapStringsSep ", " (s: "\"" + s + "\"") cfg.corsOrigins} ]; + CORS_ORIGINS = [ ${lib.concatMapStringsSep ", " (s: "\"" + s + "\"") cfg.corsOrigins} ]; AUTH_REQUIRED = ${if cfg.authenticationRequired then "True" else "False"} SIGNUP_ENABLED = ${if cfg.signupEnabled then "True" else "False"} ${cfg.extraConfig} @@ -21,64 +18,64 @@ let in { options.services.alerta = { - enable = mkEnableOption "alerta"; + enable = lib.mkEnableOption "alerta"; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 5000; description = "Port of Alerta"; }; - bind = mkOption { - type = types.str; + bind = lib.mkOption { + type = lib.types.str; default = "0.0.0.0"; description = "Address to bind to. The default is to bind to all addresses"; }; - logDir = mkOption { - type = types.path; + logDir = lib.mkOption { + type = lib.types.path; description = "Location where the logfiles are stored"; default = "/var/log/alerta"; }; - databaseUrl = mkOption { - type = types.str; + databaseUrl = lib.mkOption { + type = lib.types.str; description = "URL of the MongoDB or PostgreSQL database to connect to"; default = "mongodb://localhost"; }; - databaseName = mkOption { - type = types.str; + databaseName = lib.mkOption { + type = lib.types.str; description = "Name of the database instance to connect to"; default = "monitoring"; }; - corsOrigins = mkOption { - type = types.listOf types.str; + corsOrigins = lib.mkOption { + type = lib.types.listOf lib.types.str; description = "List of URLs that can access the API for Cross-Origin Resource Sharing (CORS)"; default = [ "http://localhost" "http://localhost:5000" ]; }; - authenticationRequired = mkOption { - type = types.bool; + authenticationRequired = lib.mkOption { + type = lib.types.bool; description = "Whether users must authenticate when using the web UI or command-line tool"; default = false; }; - signupEnabled = mkOption { - type = types.bool; + signupEnabled = lib.mkOption { + type = lib.types.bool; description = "Whether to prevent sign-up of new users via the web UI"; default = true; }; - extraConfig = mkOption { + extraConfig = lib.mkOption { description = "These lines go into alertad.conf verbatim."; default = ""; - type = types.lines; + type = lib.types.lines; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.tmpfiles.settings."10-alerta".${cfg.logDir}.d = { user = "alerta"; group = "alerta"; From 03ba605ab0882d6e809611795bef88e9f28d1dea Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:54 +0200 Subject: [PATCH 101/166] nixos/services.alloy: remove `with lib;` --- nixos/modules/services/monitoring/alloy.nix | 15 +++++++-------- 1 file changed, 7 insertions(+), 8 deletions(-) diff --git a/nixos/modules/services/monitoring/alloy.nix b/nixos/modules/services/monitoring/alloy.nix index abe8fcd7e1be..8507900756b6 100644 --- a/nixos/modules/services/monitoring/alloy.nix +++ b/nixos/modules/services/monitoring/alloy.nix @@ -1,19 +1,18 @@ { lib, pkgs, config, ... }: -with lib; let cfg = config.services.alloy; in { meta = { - maintainers = with maintainers; [ flokli hbjydev ]; + maintainers = with lib.maintainers; [ flokli hbjydev ]; }; options.services.alloy = { - enable = mkEnableOption "Grafana Alloy"; + enable = lib.mkEnableOption "Grafana Alloy"; - package = mkPackageOption pkgs "grafana-alloy" { }; + package = lib.mkPackageOption pkgs "grafana-alloy" { }; - configPath = mkOption { + configPath = lib.mkOption { type = lib.types.path; default = "/etc/alloy"; description = '' @@ -43,7 +42,7 @@ in ''; }; - extraFlags = mkOption { + extraFlags = lib.mkOption { type = with lib.types; listOf str; default = [ ]; example = [ "--server.http.listen-addr=127.0.0.1:12346" "--disable-reporting" ]; @@ -56,7 +55,7 @@ in }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.alloy = { wantedBy = [ "multi-user.target" ]; reloadTriggers = [ config.environment.etc."alloy/config.alloy".source or null ]; @@ -68,7 +67,7 @@ in # allow to read the systemd journal for loki log forwarding "systemd-journal" ]; - ExecStart = "${lib.getExe cfg.package} run ${cfg.configPath} ${escapeShellArgs cfg.extraFlags}"; + ExecStart = "${lib.getExe cfg.package} run ${cfg.configPath} ${lib.escapeShellArgs cfg.extraFlags}"; ExecReload = "${pkgs.coreutils}/bin/kill -SIGHUP $MAINPID"; ConfigurationDirectory = "alloy"; StateDirectory = "alloy"; From 3fa1cc4f5fa3ad4a468cf7f3bdad64f96a7c0fe2 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:54 +0200 Subject: [PATCH 102/166] nixos/services.apcupsd: remove `with lib;` --- nixos/modules/services/monitoring/apcupsd.nix | 21 ++++++++----------- 1 file changed, 9 insertions(+), 12 deletions(-) diff --git a/nixos/modules/services/monitoring/apcupsd.nix b/nixos/modules/services/monitoring/apcupsd.nix index 09cf593f5d5e..21b27cb3f520 100644 --- a/nixos/modules/services/monitoring/apcupsd.nix +++ b/nixos/modules/services/monitoring/apcupsd.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.apcupsd; @@ -58,7 +55,7 @@ let rm "$out/apcupsd.conf" # Set the SCRIPTDIR= line in apccontrol to the dir we're creating now sed -i -e "s|^SCRIPTDIR=.*|SCRIPTDIR=$out|" "$out/apccontrol" - '' + concatStringsSep "\n" (map eventToShellCmds eventList) + '' + lib.concatStringsSep "\n" (map eventToShellCmds eventList) ); @@ -87,9 +84,9 @@ in services.apcupsd = { - enable = mkOption { + enable = lib.mkOption { default = false; - type = types.bool; + type = lib.types.bool; description = '' Whether to enable the APC UPS daemon. apcupsd monitors your UPS and permits orderly shutdown of your computer in the event of a power @@ -99,14 +96,14 @@ in ''; }; - configText = mkOption { + configText = lib.mkOption { default = '' UPSTYPE usb NISIP 127.0.0.1 BATTERYLEVEL 50 MINUTES 5 ''; - type = types.lines; + type = lib.types.lines; description = '' Contents of the runtime configuration file, apcupsd.conf. The default settings makes apcupsd autodetect USB UPSes, limit network access to @@ -116,12 +113,12 @@ in ''; }; - hooks = mkOption { + hooks = lib.mkOption { default = {}; example = { doshutdown = "# shell commands to notify that the computer is shutting down"; }; - type = types.attrsOf types.lines; + type = lib.types.attrsOf lib.types.lines; description = '' Each attribute in this option names an apcupsd event and the string value it contains will be executed in a shell, in response to that @@ -141,10 +138,10 @@ in ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { assertions = [ { - assertion = let hooknames = builtins.attrNames cfg.hooks; in all (x: elem x eventList) hooknames; + assertion = let hooknames = builtins.attrNames cfg.hooks; in lib.all (x: lib.elem x eventList) hooknames; message = '' One (or more) attribute names in services.apcupsd.hooks are invalid. Current attribute names: ${toString (builtins.attrNames cfg.hooks)} From 7123ef8458a9dd785294e09c36fcb1ccb1a1f0bb Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:54 +0200 Subject: [PATCH 103/166] nixos/services.arbtt: remove `with lib;` --- nixos/modules/services/monitoring/arbtt.nix | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-) diff --git a/nixos/modules/services/monitoring/arbtt.nix b/nixos/modules/services/monitoring/arbtt.nix index cf9a236c079c..9c04e4447c73 100644 --- a/nixos/modules/services/monitoring/arbtt.nix +++ b/nixos/modules/services/monitoring/arbtt.nix @@ -1,18 +1,15 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.arbtt; in { options = { services.arbtt = { - enable = mkEnableOption "Arbtt statistics capture service"; + enable = lib.mkEnableOption "Arbtt statistics capture service"; - package = mkPackageOption pkgs [ "haskellPackages" "arbtt" ] { }; + package = lib.mkPackageOption pkgs [ "haskellPackages" "arbtt" ] { }; - logFile = mkOption { - type = types.str; + logFile = lib.mkOption { + type = lib.types.str; default = "%h/.arbtt/capture.log"; example = "/home/username/.arbtt-capture.log"; description = '' @@ -20,8 +17,8 @@ in { ''; }; - sampleRate = mkOption { - type = types.int; + sampleRate = lib.mkOption { + type = lib.types.int; default = 60; example = 120; description = '' @@ -31,7 +28,7 @@ in { }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.user.services.arbtt = { description = "arbtt statistics capture service"; wantedBy = [ "graphical-session.target" ]; From 66ea353e1c012916945ea431bae90d70866a4b53 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:55 +0200 Subject: [PATCH 104/166] nixos/services.below: remove `with lib;` --- nixos/modules/services/monitoring/below.nix | 41 ++++++++++----------- 1 file changed, 20 insertions(+), 21 deletions(-) diff --git a/nixos/modules/services/monitoring/below.nix b/nixos/modules/services/monitoring/below.nix index 729734828142..26a38e5f82a4 100644 --- a/nixos/modules/services/monitoring/below.nix +++ b/nixos/modules/services/monitoring/below.nix @@ -1,32 +1,31 @@ { config, lib, pkgs, ... }: -with lib; let cfg = config.services.below; - cfgContents = concatStringsSep "\n" ( - mapAttrsToList (n: v: ''${n} = "${v}"'') (filterAttrs (_k: v: v != null) { + cfgContents = lib.concatStringsSep "\n" ( + lib.mapAttrsToList (n: v: ''${n} = "${v}"'') (lib.filterAttrs (_k: v: v != null) { log_dir = cfg.dirs.log; store_dir = cfg.dirs.store; cgroup_filter_out = cfg.cgroupFilterOut; }) ); - mkDisableOption = n: mkOption { - type = types.bool; + mkDisableOption = n: lib.mkOption { + type = lib.types.bool; default = true; description = "Whether to enable ${n}."; }; - optionalType = ty: x: mkOption (x // { + optionalType = ty: x: lib.mkOption (x // { description = x.description; - type = (types.nullOr ty); + type = (lib.types.nullOr ty); default = null; }); - optionalPath = optionalType types.path; - optionalStr = optionalType types.str; - optionalInt = optionalType types.int; + optionalPath = optionalType lib.types.path; + optionalStr = optionalType lib.types.str; + optionalInt = optionalType lib.types.int; in { options = { services.below = { - enable = mkEnableOption "'below' resource monitor"; + enable = lib.mkEnableOption "'below' resource monitor"; cgroupFilterOut = optionalStr { description = "A regexp matching the full paths of cgroups whose data shouldn't be collected"; @@ -34,10 +33,10 @@ in { }; collect = { diskStats = mkDisableOption "dist_stat collection"; - ioStats = mkEnableOption "io.stat collection for cgroups"; + ioStats = lib.mkEnableOption "io.stat collection for cgroups"; exitStats = mkDisableOption "eBPF-based exitstats"; }; - compression.enable = mkEnableOption "data compression"; + compression.enable = lib.mkEnableOption "data compression"; retention = { size = optionalInt { description = '' @@ -75,7 +74,7 @@ in { }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = [ pkgs.below ]; # /etc/below.conf is also refered to by the `below` CLI tool, # so this can't be a store-only file whose path is passed to the service @@ -90,14 +89,14 @@ in { serviceConfig.ExecStart = [ "" - ("${lib.getExe pkgs.below} record " + (concatStringsSep " " ( - optional (!cfg.collect.diskStats) "--disable-disk-stat" ++ - optional cfg.collect.ioStats "--collect-io-stat" ++ - optional (!cfg.collect.exitStats) "--disable-exitstats" ++ - optional cfg.compression.enable "--compress" ++ + ("${lib.getExe pkgs.below} record " + (lib.concatStringsSep " " ( + lib.optional (!cfg.collect.diskStats) "--disable-disk-stat" ++ + lib.optional cfg.collect.ioStats "--collect-io-stat" ++ + lib.optional (!cfg.collect.exitStats) "--disable-exitstats" ++ + lib.optional cfg.compression.enable "--compress" ++ - optional (cfg.retention.size != null) "--store-size-limit ${toString cfg.retention.size}" ++ - optional (cfg.retention.time != null) "--retain-for-s ${toString cfg.retention.time}" + lib.optional (cfg.retention.size != null) "--store-size-limit ${toString cfg.retention.size}" ++ + lib.optional (cfg.retention.time != null) "--retain-for-s ${toString cfg.retention.time}" ))) ]; }; From 278fc7501c9cc7e710dc56c6e6699bf90d636a79 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:55 +0200 Subject: [PATCH 105/166] nixos/services.bosun: remove `with lib;` --- nixos/modules/services/monitoring/bosun.nix | 49 ++++++++++----------- 1 file changed, 23 insertions(+), 26 deletions(-) diff --git a/nixos/modules/services/monitoring/bosun.nix b/nixos/modules/services/monitoring/bosun.nix index 4b855b96e949..08288f644e77 100644 --- a/nixos/modules/services/monitoring/bosun.nix +++ b/nixos/modules/services/monitoring/bosun.nix @@ -1,13 +1,10 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.bosun; configFile = pkgs.writeText "bosun.conf" '' - ${optionalString (cfg.opentsdbHost !=null) "tsdbHost = ${cfg.opentsdbHost}"} - ${optionalString (cfg.influxHost !=null) "influxHost = ${cfg.influxHost}"} + ${lib.optionalString (cfg.opentsdbHost !=null) "tsdbHost = ${cfg.opentsdbHost}"} + ${lib.optionalString (cfg.influxHost !=null) "influxHost = ${cfg.influxHost}"} httpListen = ${cfg.listenAddress} stateFile = ${cfg.stateFile} ledisDir = ${cfg.ledisDir} @@ -22,28 +19,28 @@ in { services.bosun = { - enable = mkEnableOption "bosun"; + enable = lib.mkEnableOption "bosun"; - package = mkPackageOption pkgs "bosun" { }; + package = lib.mkPackageOption pkgs "bosun" { }; - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; default = "bosun"; description = '' User account under which bosun runs. ''; }; - group = mkOption { - type = types.str; + group = lib.mkOption { + type = lib.types.str; default = "bosun"; description = '' Group account under which bosun runs. ''; }; - opentsdbHost = mkOption { - type = types.nullOr types.str; + opentsdbHost = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = "localhost:4242"; description = '' Host and port of the OpenTSDB database that stores bosun data. @@ -51,8 +48,8 @@ in { ''; }; - influxHost = mkOption { - type = types.nullOr types.str; + influxHost = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; example = "localhost:8086"; description = '' @@ -60,40 +57,40 @@ in { ''; }; - listenAddress = mkOption { - type = types.str; + listenAddress = lib.mkOption { + type = lib.types.str; default = ":8070"; description = '' The host address and port that bosun's web interface will listen on. ''; }; - stateFile = mkOption { - type = types.path; + stateFile = lib.mkOption { + type = lib.types.path; default = "/var/lib/bosun/bosun.state"; description = '' Path to bosun's state file. ''; }; - ledisDir = mkOption { - type = types.path; + ledisDir = lib.mkOption { + type = lib.types.path; default = "/var/lib/bosun/ledis_data"; description = '' Path to bosun's ledis data dir ''; }; - checkFrequency = mkOption { - type = types.str; + checkFrequency = lib.mkOption { + type = lib.types.str; default = "5m"; description = '' Bosun's check frequency ''; }; - extraConfig = mkOption { - type = types.lines; + extraConfig = lib.mkOption { + type = lib.types.lines; default = ""; description = '' Extra configuration options for Bosun. You should describe your @@ -109,7 +106,7 @@ in { }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.bosun = { description = "bosun metrics collector (part of Bosun)"; From 5ced735a898a49dbfa68e28a54170f36593fe225 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:55 +0200 Subject: [PATCH 106/166] nixos/services.cadvisor: remove `with lib;` --- .../modules/services/monitoring/cadvisor.nix | 63 +++++++++---------- 1 file changed, 30 insertions(+), 33 deletions(-) diff --git a/nixos/modules/services/monitoring/cadvisor.nix b/nixos/modules/services/monitoring/cadvisor.nix index 6b0852cfe3ef..b801cde833d6 100644 --- a/nixos/modules/services/monitoring/cadvisor.nix +++ b/nixos/modules/services/monitoring/cadvisor.nix @@ -1,55 +1,52 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.services.cadvisor; in { options = { services.cadvisor = { - enable = mkEnableOption "Cadvisor service"; + enable = lib.mkEnableOption "Cadvisor service"; - listenAddress = mkOption { + listenAddress = lib.mkOption { default = "127.0.0.1"; - type = types.str; + type = lib.types.str; description = "Cadvisor listening host"; }; - port = mkOption { + port = lib.mkOption { default = 8080; - type = types.port; + type = lib.types.port; description = "Cadvisor listening port"; }; - storageDriver = mkOption { + storageDriver = lib.mkOption { default = null; - type = types.nullOr types.str; + type = lib.types.nullOr lib.types.str; example = "influxdb"; description = "Cadvisor storage driver."; }; - storageDriverHost = mkOption { + storageDriverHost = lib.mkOption { default = "localhost:8086"; - type = types.str; + type = lib.types.str; description = "Cadvisor storage driver host."; }; - storageDriverDb = mkOption { + storageDriverDb = lib.mkOption { default = "root"; - type = types.str; + type = lib.types.str; description = "Cadvisord storage driver database name."; }; - storageDriverUser = mkOption { + storageDriverUser = lib.mkOption { default = "root"; - type = types.str; + type = lib.types.str; description = "Cadvisor storage driver username."; }; - storageDriverPassword = mkOption { + storageDriverPassword = lib.mkOption { default = "root"; - type = types.str; + type = lib.types.str; description = '' Cadvisor storage driver password. @@ -60,8 +57,8 @@ in { ''; }; - storageDriverPasswordFile = mkOption { - type = types.str; + storageDriverPasswordFile = lib.mkOption { + type = lib.types.str; description = '' File that contains the cadvisor storage driver password. @@ -75,14 +72,14 @@ in { ''; }; - storageDriverSecure = mkOption { + storageDriverSecure = lib.mkOption { default = false; - type = types.bool; + type = lib.types.bool; description = "Cadvisor storage driver, enable secure communication."; }; - extraOptions = mkOption { - type = types.listOf types.str; + extraOptions = lib.mkOption { + type = lib.types.listOf lib.types.str; default = []; description = '' Additional cadvisor options. @@ -93,23 +90,23 @@ in { }; }; - config = mkMerge [ - { services.cadvisor.storageDriverPasswordFile = mkIf (cfg.storageDriverPassword != "") ( - mkDefault (toString (pkgs.writeTextFile { + config = lib.mkMerge [ + { services.cadvisor.storageDriverPasswordFile = lib.mkIf (cfg.storageDriverPassword != "") ( + lib.mkDefault (toString (pkgs.writeTextFile { name = "cadvisor-storage-driver-password"; text = cfg.storageDriverPassword; })) ); } - (mkIf cfg.enable { + (lib.mkIf cfg.enable { systemd.services.cadvisor = { wantedBy = [ "multi-user.target" ]; after = [ "network.target" "docker.service" "influxdb.service" ]; - path = optionals config.boot.zfs.enabled [ pkgs.zfs ]; + path = lib.optionals config.boot.zfs.enabled [ pkgs.zfs ]; - postStart = mkBefore '' + postStart = lib.mkBefore '' until ${pkgs.curl.bin}/bin/curl -s -o /dev/null 'http://${cfg.listenAddress}:${toString cfg.port}/containers/'; do sleep 1; done @@ -120,14 +117,14 @@ in { -logtostderr=true \ -listen_ip="${cfg.listenAddress}" \ -port="${toString cfg.port}" \ - ${escapeShellArgs cfg.extraOptions} \ - ${optionalString (cfg.storageDriver != null) '' + ${lib.escapeShellArgs cfg.extraOptions} \ + ${lib.optionalString (cfg.storageDriver != null) '' -storage_driver "${cfg.storageDriver}" \ -storage_driver_host "${cfg.storageDriverHost}" \ -storage_driver_db "${cfg.storageDriverDb}" \ -storage_driver_user "${cfg.storageDriverUser}" \ -storage_driver_password "$(cat "${cfg.storageDriverPasswordFile}")" \ - ${optionalString cfg.storageDriverSecure "-storage_driver_secure"} + ${lib.optionalString cfg.storageDriverSecure "-storage_driver_secure"} ''} ''; From c39797b55e3bfcbfe4205c2a1aa35ab75ee05cc6 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:55 +0200 Subject: [PATCH 107/166] nixos/services.collectd: remove `with lib;` --- .../modules/services/monitoring/collectd.nix | 37 +++++++++---------- 1 file changed, 17 insertions(+), 20 deletions(-) diff --git a/nixos/modules/services/monitoring/collectd.nix b/nixos/modules/services/monitoring/collectd.nix index fe9b1214e5c1..1bd7da52fef8 100644 --- a/nixos/modules/services/monitoring/collectd.nix +++ b/nixos/modules/services/monitoring/collectd.nix @@ -1,7 +1,4 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.services.collectd; @@ -28,10 +25,10 @@ let }; in { - options.services.collectd = with types; { - enable = mkEnableOption "collectd agent"; + options.services.collectd = with lib.types; { + enable = lib.mkEnableOption "collectd agent"; - validateConfig = mkOption { + validateConfig = lib.mkOption { default = true; description = '' Validate the syntax of collectd configuration file at build time. @@ -41,9 +38,9 @@ in { type = types.bool; }; - package = mkPackageOption pkgs "collectd" { }; + package = lib.mkPackageOption pkgs "collectd" { }; - buildMinimalPackage = mkOption { + buildMinimalPackage = lib.mkOption { default = false; description = '' Build a minimal collectd package with only the configured `services.collectd.plugins` @@ -51,7 +48,7 @@ in { type = bool; }; - user = mkOption { + user = lib.mkOption { default = "collectd"; description = '' User under which to run collectd. @@ -59,7 +56,7 @@ in { type = nullOr str; }; - dataDir = mkOption { + dataDir = lib.mkOption { default = "/var/lib/collectd"; description = '' Data directory for collectd agent. @@ -67,7 +64,7 @@ in { type = path; }; - autoLoadPlugin = mkOption { + autoLoadPlugin = lib.mkOption { default = false; description = '' Enable plugin autoloading. @@ -75,7 +72,7 @@ in { type = bool; }; - include = mkOption { + include = lib.mkOption { default = []; description = '' Additional paths to load config from. @@ -83,7 +80,7 @@ in { type = listOf str; }; - plugins = mkOption { + plugins = lib.mkOption { default = {}; example = { cpu = ""; memory = ""; network = "Server 192.168.1.1 25826"; }; description = '' @@ -92,7 +89,7 @@ in { type = attrsOf lines; }; - extraConfig = mkOption { + extraConfig = lib.mkOption { default = ""; description = '' Extra configuration for collectd. Use mkBefore to add lines before the @@ -103,11 +100,11 @@ in { }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { # 1200 is after the default (1000) but before mkAfter (1500). services.collectd.extraConfig = lib.mkOrder 1200 '' ${baseDirLine} - AutoLoadPlugin ${boolToString cfg.autoLoadPlugin} + AutoLoadPlugin ${lib.boolToString cfg.autoLoadPlugin} Hostname "${config.networking.hostName}" LoadPlugin syslog @@ -116,14 +113,14 @@ in { NotifyLevel "OKAY" - ${concatStrings (mapAttrsToList (plugin: pluginConfig: '' + ${lib.concatStrings (lib.mapAttrsToList (plugin: pluginConfig: '' LoadPlugin ${plugin} ${pluginConfig} '') cfg.plugins)} - ${concatMapStrings (f: '' + ${lib.concatMapStrings (f: '' Include "${f}" '') cfg.include} ''; @@ -145,14 +142,14 @@ in { }; }; - users.users = optionalAttrs (cfg.user == "collectd") { + users.users = lib.optionalAttrs (cfg.user == "collectd") { collectd = { isSystemUser = true; group = "collectd"; }; }; - users.groups = optionalAttrs (cfg.user == "collectd") { + users.groups = lib.optionalAttrs (cfg.user == "collectd") { collectd = {}; }; }; From 357422f21b05c7dd783c2b3e21df452a329bc5a7 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:56 +0200 Subject: [PATCH 108/166] nixos/services.das_watchdog: remove `with lib;` --- nixos/modules/services/monitoring/das_watchdog.nix | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/nixos/modules/services/monitoring/das_watchdog.nix b/nixos/modules/services/monitoring/das_watchdog.nix index 88ca3a9227d2..e076bf64364e 100644 --- a/nixos/modules/services/monitoring/das_watchdog.nix +++ b/nixos/modules/services/monitoring/das_watchdog.nix @@ -1,9 +1,6 @@ # A general watchdog for the linux operating system that should run in the # background at all times to ensure a realtime process won't hang the machine { config, lib, pkgs, ... }: - -with lib; - let inherit (pkgs) das_watchdog; @@ -12,12 +9,12 @@ in { ###### interface options = { - services.das_watchdog.enable = mkEnableOption "realtime watchdog"; + services.das_watchdog.enable = lib.mkEnableOption "realtime watchdog"; }; ###### implementation - config = mkIf config.services.das_watchdog.enable { + config = lib.mkIf config.services.das_watchdog.enable { environment.systemPackages = [ das_watchdog ]; systemd.services.das_watchdog = { description = "Watchdog to ensure a realtime process won't hang the machine"; From 4bfa9c3f97c4e79ab2b4c54638eb51ab5ed2995b Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:56 +0200 Subject: [PATCH 109/166] nixos/services.datadog-agent: remove `with lib;` --- .../services/monitoring/datadog-agent.nix | 89 +++++++++---------- 1 file changed, 43 insertions(+), 46 deletions(-) diff --git a/nixos/modules/services/monitoring/datadog-agent.nix b/nixos/modules/services/monitoring/datadog-agent.nix index 04232b3c9346..8256226041ea 100644 --- a/nixos/modules/services/monitoring/datadog-agent.nix +++ b/nixos/modules/services/monitoring/datadog-agent.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.datadog-agent; @@ -11,19 +8,19 @@ let additional_checksd = "/etc/datadog-agent/checks.d"; use_dogstatsd = true; } - // optionalAttrs (cfg.logLevel != null) { log_level = cfg.logLevel; } - // optionalAttrs (cfg.hostname != null) { inherit (cfg) hostname; } - // optionalAttrs (cfg.ddUrl != null) { dd_url = cfg.ddUrl; } - // optionalAttrs (cfg.site != null) { site = cfg.site; } - // optionalAttrs (cfg.tags != null ) { tags = concatStringsSep ", " cfg.tags; } - // optionalAttrs (cfg.enableLiveProcessCollection) { process_config = { enabled = "true"; }; } - // optionalAttrs (cfg.enableTraceAgent) { apm_config = { enabled = true; }; } + // lib.optionalAttrs (cfg.logLevel != null) { log_level = cfg.logLevel; } + // lib.optionalAttrs (cfg.hostname != null) { inherit (cfg) hostname; } + // lib.optionalAttrs (cfg.ddUrl != null) { dd_url = cfg.ddUrl; } + // lib.optionalAttrs (cfg.site != null) { site = cfg.site; } + // lib.optionalAttrs (cfg.tags != null ) { tags = lib.concatStringsSep ", " cfg.tags; } + // lib.optionalAttrs (cfg.enableLiveProcessCollection) { process_config = { enabled = "true"; }; } + // lib.optionalAttrs (cfg.enableTraceAgent) { apm_config = { enabled = true; }; } // cfg.extraConfig; # Generate Datadog configuration files for each configured checks. # This works because check configurations have predictable paths, # and because JSON is a valid subset of YAML. - makeCheckConfigs = entries: mapAttrs' (name: conf: { + makeCheckConfigs = entries: lib.mapAttrs' (name: conf: { name = "datadog-agent/conf.d/${name}.d/conf.yaml"; value.source = pkgs.writeText "${name}-check-conf.yaml" (builtins.toJSON conf); }) entries; @@ -49,9 +46,9 @@ let }; in { options.services.datadog-agent = { - enable = mkEnableOption "Datadog-agent v7 monitoring service"; + enable = lib.mkEnableOption "Datadog-agent v7 monitoring service"; - package = mkPackageOption pkgs "datadog-agent" { + package = lib.mkPackageOption pkgs "datadog-agent" { extraDescription = '' ::: {.note} The provided package is expected to have an overridable `pythonPackages`-attribute @@ -60,16 +57,16 @@ in { ''; }; - apiKeyFile = mkOption { + apiKeyFile = lib.mkOption { description = '' Path to a file containing the Datadog API key to associate the agent with your account. ''; example = "/run/keys/datadog_api_key"; - type = types.path; + type = lib.types.path; }; - ddUrl = mkOption { + ddUrl = lib.mkOption { description = '' Custom dd_url to configure the agent with. Useful if traffic to datadog needs to go through a proxy. @@ -77,42 +74,42 @@ in { ''; default = null; example = "http://haproxy.example.com:3834"; - type = types.nullOr types.str; + type = lib.types.nullOr lib.types.str; }; - site = mkOption { + site = lib.mkOption { description = '' The datadog site to point the agent towards. Set to datadoghq.eu to point it to their EU site. ''; default = null; example = "datadoghq.eu"; - type = types.nullOr types.str; + type = lib.types.nullOr lib.types.str; }; - tags = mkOption { + tags = lib.mkOption { description = "The tags to mark this Datadog agent"; example = [ "test" "service" ]; default = null; - type = types.nullOr (types.listOf types.str); + type = lib.types.nullOr (lib.types.listOf lib.types.str); }; - hostname = mkOption { + hostname = lib.mkOption { description = "The hostname to show in the Datadog dashboard (optional)"; default = null; example = "mymachine.mydomain"; - type = types.nullOr types.str; + type = lib.types.nullOr lib.types.str; }; - logLevel = mkOption { + logLevel = lib.mkOption { description = "Logging verbosity."; default = null; - type = types.nullOr (types.enum ["DEBUG" "INFO" "WARN" "ERROR"]); + type = lib.types.nullOr (lib.types.enum ["DEBUG" "INFO" "WARN" "ERROR"]); }; - extraIntegrations = mkOption { + extraIntegrations = lib.mkOption { default = {}; - type = types.attrs; + type = lib.types.attrs; description = '' Extra integrations from the Datadog core-integrations @@ -126,51 +123,51 @@ in { package set must be provided. ''; - example = literalExpression '' + example = lib.literalExpression '' { ntp = pythonPackages: [ pythonPackages.ntplib ]; } ''; }; - extraConfig = mkOption { + extraConfig = lib.mkOption { default = {}; - type = types.attrs; + type = lib.types.attrs; description = '' Extra configuration options that will be merged into the main config file {file}`datadog.yaml`. ''; }; - enableLiveProcessCollection = mkOption { + enableLiveProcessCollection = lib.mkOption { description = '' Whether to enable the live process collection agent. ''; default = false; - type = types.bool; + type = lib.types.bool; }; - processAgentPackage = mkOption { + processAgentPackage = lib.mkOption { default = pkgs.datadog-process-agent; - defaultText = literalExpression "pkgs.datadog-process-agent"; + defaultText = lib.literalExpression "pkgs.datadog-process-agent"; description = '' Which DataDog v7 agent package to use. Note that the provided package is expected to have an overridable `pythonPackages`-attribute which configures the Python environment with the Datadog checks. ''; - type = types.package; + type = lib.types.package; }; - enableTraceAgent = mkOption { + enableTraceAgent = lib.mkOption { description = '' Whether to enable the trace agent. ''; default = false; - type = types.bool; + type = lib.types.bool; }; - checks = mkOption { + checks = lib.mkOption { description = '' Configuration for all Datadog checks. Keys of this attribute set will be used as the name of the check to create the @@ -206,21 +203,21 @@ in { # sic! The structure of the values is up to the check, so we can # not usefully constrain the type further. - type = with types; attrsOf attrs; + type = with lib.types; attrsOf attrs; }; - diskCheck = mkOption { + diskCheck = lib.mkOption { description = "Disk check config"; - type = types.attrs; + type = lib.types.attrs; default = { init_config = {}; instances = [ { use_mount = "false"; } ]; }; }; - networkCheck = mkOption { + networkCheck = lib.mkOption { description = "Network check config"; - type = types.attrs; + type = lib.types.attrs; default = { init_config = {}; # Network check only supports one configured instance @@ -229,7 +226,7 @@ in { }; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = [ datadogPkg pkgs.sysstat pkgs.procps pkgs.iproute2 ]; users.users.datadog = { @@ -243,7 +240,7 @@ in { users.groups.datadog.gid = config.ids.gids.datadog; systemd.services = let - makeService = attrs: recursiveUpdate { + makeService = attrs: lib.recursiveUpdate { path = [ datadogPkg pkgs.sysstat pkgs.procps pkgs.iproute2 ]; wantedBy = [ "multi-user.target" ]; serviceConfig = { @@ -252,7 +249,7 @@ in { Restart = "always"; RestartSec = 2; }; - restartTriggers = [ datadogPkg ] ++ map (x: x.source) (attrValues etcfiles); + restartTriggers = [ datadogPkg ] ++ map (x: x.source) (lib.attrValues etcfiles); } attrs; in { datadog-agent = makeService { From 699ee515a14268a8661b057dfecc7b890117c7a3 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:56 +0200 Subject: [PATCH 110/166] nixos/services.do-agent: remove `with lib;` --- nixos/modules/services/monitoring/do-agent.nix | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/nixos/modules/services/monitoring/do-agent.nix b/nixos/modules/services/monitoring/do-agent.nix index 4dfb6236727b..e5f1bdf7fdfc 100644 --- a/nixos/modules/services/monitoring/do-agent.nix +++ b/nixos/modules/services/monitoring/do-agent.nix @@ -1,17 +1,14 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.do-agent; in { options.services.do-agent = { - enable = mkEnableOption "do-agent, the DigitalOcean droplet metrics agent"; + enable = lib.mkEnableOption "do-agent, the DigitalOcean droplet metrics agent"; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.packages = [ pkgs.do-agent ]; systemd.services.do-agent = { From 69dd091d5150303ca3fbbc76dbbf512832c92d0c Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:56 +0200 Subject: [PATCH 111/166] nixos/services.fusionInventory: remove `with lib;` --- .../services/monitoring/fusion-inventory.nix | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-) diff --git a/nixos/modules/services/monitoring/fusion-inventory.nix b/nixos/modules/services/monitoring/fusion-inventory.nix index 9b65c76ce02e..cb6c8a827390 100644 --- a/nixos/modules/services/monitoring/fusion-inventory.nix +++ b/nixos/modules/services/monitoring/fusion-inventory.nix @@ -1,13 +1,10 @@ # Fusion Inventory daemon. { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.fusionInventory; configFile = pkgs.writeText "fusion_inventory.conf" '' - server = ${concatStringsSep ", " cfg.servers} + server = ${lib.concatStringsSep ", " cfg.servers} logger = stderr @@ -22,18 +19,18 @@ in { services.fusionInventory = { - enable = mkEnableOption "Fusion Inventory Agent"; + enable = lib.mkEnableOption "Fusion Inventory Agent"; - servers = mkOption { - type = types.listOf types.str; + servers = lib.mkOption { + type = lib.types.listOf lib.types.str; description = '' The urls of the OCS/GLPI servers to connect to. ''; }; - extraConfig = mkOption { + extraConfig = lib.mkOption { default = ""; - type = types.lines; + type = lib.types.lines; description = '' Configuration that is injected verbatim into the configuration file. ''; @@ -44,7 +41,7 @@ in { ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { users.users.fusion-inventory = { description = "FusionInventory user"; From e86917ad30012fa0a0998e1b86797263c90cccdc Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:57 +0200 Subject: [PATCH 112/166] nixos/services.grafana-agent: remove `with lib;` --- .../services/monitoring/grafana-agent.nix | 33 +++++++++---------- 1 file changed, 16 insertions(+), 17 deletions(-) diff --git a/nixos/modules/services/monitoring/grafana-agent.nix b/nixos/modules/services/monitoring/grafana-agent.nix index 655ec8ded1e0..f82675c8c6cb 100644 --- a/nixos/modules/services/monitoring/grafana-agent.nix +++ b/nixos/modules/services/monitoring/grafana-agent.nix @@ -1,5 +1,4 @@ { lib, pkgs, config, generators, ... }: -with lib; let cfg = config.services.grafana-agent; settingsFormat = pkgs.formats.yaml { }; @@ -7,19 +6,19 @@ let in { meta = { - maintainers = with maintainers; [ flokli zimbatm ]; + maintainers = with lib.maintainers; [ flokli zimbatm ]; }; options.services.grafana-agent = { - enable = mkEnableOption "grafana-agent"; + enable = lib.mkEnableOption "grafana-agent"; - package = mkPackageOption pkgs "grafana-agent" { }; + package = lib.mkPackageOption pkgs "grafana-agent" { }; - credentials = mkOption { + credentials = lib.mkOption { description = '' Credentials to load at service startup. Keys that are UPPER_SNAKE will be loaded as env vars. Values are absolute paths to the credentials. ''; - type = types.attrsOf types.str; + type = lib.types.attrsOf lib.types.str; default = { }; example = { @@ -32,8 +31,8 @@ in }; }; - extraFlags = mkOption { - type = with types; listOf str; + extraFlags = lib.mkOption { + type = with lib.types; listOf str; default = [ ]; example = [ "-enable-features=integrations-next" "-disable-reporting" ]; description = '' @@ -43,14 +42,14 @@ in ''; }; - settings = mkOption { + settings = lib.mkOption { description = '' Configuration for {command}`grafana-agent`. See ''; - type = types.submodule { + type = lib.types.submodule { freeformType = settingsFormat.type; }; @@ -110,17 +109,17 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { services.grafana-agent.settings = { # keep this in sync with config.services.grafana-agent.settings.defaultText. metrics = { - wal_directory = mkDefault "\${STATE_DIRECTORY}"; - global.scrape_interval = mkDefault "5s"; + wal_directory = lib.mkDefault "\${STATE_DIRECTORY}"; + global.scrape_interval = lib.mkDefault "5s"; }; integrations = { - agent.enabled = mkDefault true; - agent.scrape_integration = mkDefault true; - node_exporter.enabled = mkDefault true; + agent.enabled = lib.mkDefault true; + agent.scrape_integration = lib.mkDefault true; + node_exporter.enabled = lib.mkDefault true; }; }; @@ -144,7 +143,7 @@ in # We can't use Environment=HOSTNAME=%H, as it doesn't include the domain part. export HOSTNAME=$(< /proc/sys/kernel/hostname) - exec ${lib.getExe cfg.package} -config.expand-env -config.file ${configFile} ${escapeShellArgs cfg.extraFlags} + exec ${lib.getExe cfg.package} -config.expand-env -config.file ${configFile} ${lib.escapeShellArgs cfg.extraFlags} ''; serviceConfig = { Restart = "always"; From f1019c7adb84acdbe54e9175763873c35711a28f Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:57 +0200 Subject: [PATCH 113/166] nixos/services.grafana-image-renderer: remove `with lib;` --- .../monitoring/grafana-image-renderer.nix | 55 +++++++++---------- 1 file changed, 26 insertions(+), 29 deletions(-) diff --git a/nixos/modules/services/monitoring/grafana-image-renderer.nix b/nixos/modules/services/monitoring/grafana-image-renderer.nix index e06720b15302..e477f73adaa1 100644 --- a/nixos/modules/services/monitoring/grafana-image-renderer.nix +++ b/nixos/modules/services/monitoring/grafana-image-renderer.nix @@ -1,7 +1,4 @@ { lib, pkgs, config, ... }: - -with lib; - let cfg = config.services.grafana-image-renderer; @@ -10,34 +7,34 @@ let configFile = format.generate "grafana-image-renderer-config.json" cfg.settings; in { options.services.grafana-image-renderer = { - enable = mkEnableOption "grafana-image-renderer"; + enable = lib.mkEnableOption "grafana-image-renderer"; - chromium = mkOption { - type = types.package; + chromium = lib.mkOption { + type = lib.types.package; description = '' The chromium to use for image rendering. ''; }; - verbose = mkEnableOption "verbosity for the service"; + verbose = lib.mkEnableOption "verbosity for the service"; - provisionGrafana = mkEnableOption "Grafana configuration for grafana-image-renderer"; + provisionGrafana = lib.mkEnableOption "Grafana configuration for grafana-image-renderer"; - settings = mkOption { - type = types.submodule { + settings = lib.mkOption { + type = lib.types.submodule { freeformType = format.type; options = { service = { - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 8081; description = '' The TCP port to use for the rendering server. ''; }; - logging.level = mkOption { - type = types.enum [ "error" "warning" "info" "debug" ]; + logging.level = lib.mkOption { + type = lib.types.enum [ "error" "warning" "info" "debug" ]; default = "info"; description = '' The log-level of the {file}`grafana-image-renderer.service`-unit. @@ -45,23 +42,23 @@ in { }; }; rendering = { - width = mkOption { + width = lib.mkOption { default = 1000; - type = types.ints.positive; + type = lib.types.ints.positive; description = '' Width of the PNG used to display the alerting graph. ''; }; - height = mkOption { + height = lib.mkOption { default = 500; - type = types.ints.positive; + type = lib.types.ints.positive; description = '' Height of the PNG used to display the alerting graph. ''; }; - mode = mkOption { + mode = lib.mkOption { default = "default"; - type = types.enum [ "default" "reusable" "clustered" ]; + type = lib.types.enum [ "default" "reusable" "clustered" ]; description = '' Rendering mode of `grafana-image-renderer`: @@ -74,8 +71,8 @@ in { for that mode can be declared in `rendering.clustering`. ''; }; - args = mkOption { - type = types.listOf types.str; + args = lib.mkOption { + type = lib.types.listOf lib.types.str; default = [ "--no-sandbox" ]; description = '' List of CLI flags passed to `chromium`. @@ -96,7 +93,7 @@ in { }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { assertions = [ { assertion = cfg.provisionGrafana -> config.services.grafana.enable; message = '' @@ -106,23 +103,23 @@ in { } ]; - services.grafana.settings.rendering = mkIf cfg.provisionGrafana { + services.grafana.settings.rendering = lib.mkIf cfg.provisionGrafana { server_url = "http://localhost:${toString cfg.settings.service.port}/render"; callback_url = "http://${config.services.grafana.settings.server.http_addr}:${toString config.services.grafana.settings.server.http_port}"; }; - services.grafana-image-renderer.chromium = mkDefault pkgs.chromium; + services.grafana-image-renderer.chromium = lib.mkDefault pkgs.chromium; services.grafana-image-renderer.settings = { - rendering = mapAttrs (const mkDefault) { + rendering = lib.mapAttrs (lib.const lib.mkDefault) { chromeBin = "${cfg.chromium}/bin/chromium"; verboseLogging = cfg.verbose; timezone = config.time.timeZone; }; service = { - logging.level = mkIf cfg.verbose (mkDefault "debug"); - metrics.enabled = mkDefault false; + logging.level = lib.mkIf cfg.verbose (lib.mkDefault "debug"); + metrics.enabled = lib.mkDefault false; }; }; @@ -144,5 +141,5 @@ in { }; }; - meta.maintainers = with maintainers; [ ma27 ]; + meta.maintainers = with lib.maintainers; [ ma27 ]; } From 8f9336460b3cbfdb0859919fc73cb8c8ff40a1c2 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:57 +0200 Subject: [PATCH 114/166] nixos/services.grafana_reporter: remove `with lib;` --- .../services/monitoring/grafana-reporter.nix | 33 +++++++++---------- 1 file changed, 15 insertions(+), 18 deletions(-) diff --git a/nixos/modules/services/monitoring/grafana-reporter.nix b/nixos/modules/services/monitoring/grafana-reporter.nix index 528041cab37a..91725206ea12 100644 --- a/nixos/modules/services/monitoring/grafana-reporter.nix +++ b/nixos/modules/services/monitoring/grafana-reporter.nix @@ -1,53 +1,50 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.grafana_reporter; in { options.services.grafana_reporter = { - enable = mkEnableOption "grafana_reporter"; + enable = lib.mkEnableOption "grafana_reporter"; grafana = { - protocol = mkOption { + protocol = lib.mkOption { description = "Grafana protocol."; default = "http"; - type = types.enum ["http" "https"]; + type = lib.types.enum ["http" "https"]; }; - addr = mkOption { + addr = lib.mkOption { description = "Grafana address."; default = "127.0.0.1"; - type = types.str; + type = lib.types.str; }; - port = mkOption { + port = lib.mkOption { description = "Grafana port."; default = 3000; - type = types.port; + type = lib.types.port; }; }; - addr = mkOption { + addr = lib.mkOption { description = "Listening address."; default = "127.0.0.1"; - type = types.str; + type = lib.types.str; }; - port = mkOption { + port = lib.mkOption { description = "Listening port."; default = 8686; - type = types.port; + type = lib.types.port; }; - templateDir = mkOption { + templateDir = lib.mkOption { description = "Optional template directory to use custom tex templates"; default = pkgs.grafana_reporter; - defaultText = literalExpression "pkgs.grafana_reporter"; - type = types.either types.str types.path; + defaultText = lib.literalExpression "pkgs.grafana_reporter"; + type = lib.types.either lib.types.str lib.types.path; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.grafana_reporter = { description = "Grafana Reporter Service Daemon"; wantedBy = ["multi-user.target"]; From 95e5f256d664c214befd4cd1961cf6fcd5d91e0c Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:58 +0200 Subject: [PATCH 115/166] nixos/services.hdapsd: remove `with lib;` --- nixos/modules/services/monitoring/hdaps.nix | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/nixos/modules/services/monitoring/hdaps.nix b/nixos/modules/services/monitoring/hdaps.nix index 366367ef835c..ee9b85a50ae4 100644 --- a/nixos/modules/services/monitoring/hdaps.nix +++ b/nixos/modules/services/monitoring/hdaps.nix @@ -1,20 +1,17 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.hdapsd; hdapsd = [ pkgs.hdapsd ]; in { options = { - services.hdapsd.enable = mkEnableOption '' + services.hdapsd.enable = lib.mkEnableOption '' Hard Drive Active Protection System Daemon, devices are detected and managed automatically by udev and systemd ''; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { boot.kernelModules = [ "hdapsd" ]; services.udev.packages = hdapsd; systemd.packages = hdapsd; From baece5fb08e8a82eee684e413eaefeb699a43b4a Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:58 +0200 Subject: [PATCH 116/166] nixos/services.heapster: remove `with lib;` --- .../modules/services/monitoring/heapster.nix | 21 ++++++++----------- 1 file changed, 9 insertions(+), 12 deletions(-) diff --git a/nixos/modules/services/monitoring/heapster.nix b/nixos/modules/services/monitoring/heapster.nix index b8ba3632caca..ea03ec46c55c 100644 --- a/nixos/modules/services/monitoring/heapster.nix +++ b/nixos/modules/services/monitoring/heapster.nix @@ -1,35 +1,32 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.heapster; in { options.services.heapster = { - enable = mkEnableOption "Heapster monitoring"; + enable = lib.mkEnableOption "Heapster monitoring"; - source = mkOption { + source = lib.mkOption { description = "Heapster metric source"; example = "kubernetes:https://kubernetes.default"; - type = types.str; + type = lib.types.str; }; - sink = mkOption { + sink = lib.mkOption { description = "Heapster metic sink"; example = "influxdb:http://localhost:8086"; - type = types.str; + type = lib.types.str; }; - extraOpts = mkOption { + extraOpts = lib.mkOption { description = "Heapster extra options"; default = ""; - type = types.separatedString " "; + type = lib.types.separatedString " "; }; - package = mkPackageOption pkgs "heapster" { }; + package = lib.mkPackageOption pkgs "heapster" { }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.heapster = { wantedBy = ["multi-user.target"]; after = ["cadvisor.service" "kube-apiserver.service"]; From 5b483238377ef59fa4c2ebb64e075bb4e59df783 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:58 +0200 Subject: [PATCH 117/166] nixos/services.incron: remove `with lib;` --- nixos/modules/services/monitoring/incron.nix | 38 +++++++++----------- 1 file changed, 17 insertions(+), 21 deletions(-) diff --git a/nixos/modules/services/monitoring/incron.nix b/nixos/modules/services/monitoring/incron.nix index 58b07bf97f1d..f7370e4eac23 100644 --- a/nixos/modules/services/monitoring/incron.nix +++ b/nixos/modules/services/monitoring/incron.nix @@ -1,8 +1,4 @@ - { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.incron; @@ -14,8 +10,8 @@ in services.incron = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether to enable the incron daemon. @@ -24,8 +20,8 @@ in ''; }; - allow = mkOption { - type = types.nullOr (types.listOf types.str); + allow = lib.mkOption { + type = lib.types.nullOr (lib.types.listOf lib.types.str); default = null; description = '' Users allowed to use incrontab. @@ -37,14 +33,14 @@ in ''; }; - deny = mkOption { - type = types.nullOr (types.listOf types.str); + deny = lib.mkOption { + type = lib.types.nullOr (lib.types.listOf lib.types.str); default = null; description = "Users forbidden from using incrontab."; }; - systab = mkOption { - type = types.lines; + systab = lib.mkOption { + type = lib.types.lines; default = ""; description = "The system incrontab contents."; example = '' @@ -53,10 +49,10 @@ in ''; }; - extraPackages = mkOption { - type = types.listOf types.package; + extraPackages = lib.mkOption { + type = lib.types.listOf lib.types.package; default = []; - example = literalExpression "[ pkgs.rsync ]"; + example = lib.literalExpression "[ pkgs.rsync ]"; description = "Extra packages available to the system incrontab."; }; @@ -64,9 +60,9 @@ in }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { - warnings = optional (cfg.allow != null && cfg.deny != null) + warnings = lib.optional (cfg.allow != null && cfg.deny != null) "If `services.incron.allow` is set then `services.incron.deny` will be ignored."; environment.systemPackages = [ pkgs.incron ]; @@ -83,11 +79,11 @@ in mode = "0444"; text = cfg.systab; }; - environment.etc."incron.allow" = mkIf (cfg.allow != null) { - text = concatStringsSep "\n" cfg.allow; + environment.etc."incron.allow" = lib.mkIf (cfg.allow != null) { + text = lib.concatStringsSep "\n" cfg.allow; }; - environment.etc."incron.deny" = mkIf (cfg.deny != null) { - text = concatStringsSep "\n" cfg.deny; + environment.etc."incron.deny" = lib.mkIf (cfg.deny != null) { + text = lib.concatStringsSep "\n" cfg.deny; }; systemd.services.incron = { From 588c1c985b2187281b37880f3ae6fd47353d9aaf Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:58 +0200 Subject: [PATCH 118/166] nixos/services.kapacitor: remove `with lib;` --- .../modules/services/monitoring/kapacitor.nix | 77 +++++++++---------- 1 file changed, 37 insertions(+), 40 deletions(-) diff --git a/nixos/modules/services/monitoring/kapacitor.nix b/nixos/modules/services/monitoring/kapacitor.nix index 01919e73f734..f42dfff623a0 100644 --- a/nixos/modules/services/monitoring/kapacitor.nix +++ b/nixos/modules/services/monitoring/kapacitor.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.kapacitor; @@ -26,13 +23,13 @@ let [storage] boltdb = "${cfg.dataDir}/kapacitor.db" - ${optionalString (cfg.loadDirectory != null) '' + ${lib.optionalString (cfg.loadDirectory != null) '' [load] enabled = true dir = "${cfg.loadDirectory}" ''} - ${optionalString (cfg.defaultDatabase.enable) '' + ${lib.optionalString (cfg.defaultDatabase.enable) '' [[influxdb]] name = "default" enabled = true @@ -42,7 +39,7 @@ let password = "${cfg.defaultDatabase.password}" ''} - ${optionalString (cfg.alerta.enable) '' + ${lib.optionalString (cfg.alerta.enable) '' [alerta] enabled = true url = "${cfg.alerta.url}" @@ -57,107 +54,107 @@ let in { options.services.kapacitor = { - enable = mkEnableOption "kapacitor"; + enable = lib.mkEnableOption "kapacitor"; - dataDir = mkOption { - type = types.path; + dataDir = lib.mkOption { + type = lib.types.path; default = "/var/lib/kapacitor"; description = "Location where Kapacitor stores its state"; }; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 9092; description = "Port of Kapacitor"; }; - bind = mkOption { - type = types.str; + bind = lib.mkOption { + type = lib.types.str; default = ""; example = "0.0.0.0"; description = "Address to bind to. The default is to bind to all addresses"; }; - extraConfig = mkOption { + extraConfig = lib.mkOption { description = "These lines go into kapacitord.conf verbatim."; default = ""; - type = types.lines; + type = lib.types.lines; }; - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; default = "kapacitor"; description = "User account under which Kapacitor runs"; }; - group = mkOption { - type = types.str; + group = lib.mkOption { + type = lib.types.str; default = "kapacitor"; description = "Group under which Kapacitor runs"; }; - taskSnapshotInterval = mkOption { - type = types.str; + taskSnapshotInterval = lib.mkOption { + type = lib.types.str; description = "Specifies how often to snapshot the task state (in InfluxDB time units)"; default = "1m0s"; }; - loadDirectory = mkOption { - type = types.nullOr types.path; + loadDirectory = lib.mkOption { + type = lib.types.nullOr lib.types.path; description = "Directory where to load services from, such as tasks, templates and handlers (or null to disable service loading on startup)"; default = null; }; defaultDatabase = { - enable = mkEnableOption "kapacitor.defaultDatabase"; + enable = lib.mkEnableOption "kapacitor.defaultDatabase"; - url = mkOption { + url = lib.mkOption { description = "The URL to an InfluxDB server that serves as the default database"; example = "http://localhost:8086"; - type = types.str; + type = lib.types.str; }; - username = mkOption { + username = lib.mkOption { description = "The username to connect to the remote InfluxDB server"; - type = types.str; + type = lib.types.str; }; - password = mkOption { + password = lib.mkOption { description = "The password to connect to the remote InfluxDB server"; - type = types.str; + type = lib.types.str; }; }; alerta = { - enable = mkEnableOption "kapacitor alerta integration"; + enable = lib.mkEnableOption "kapacitor alerta integration"; - url = mkOption { + url = lib.mkOption { description = "The URL to the Alerta REST API"; default = "http://localhost:5000"; - type = types.str; + type = lib.types.str; }; - token = mkOption { + token = lib.mkOption { description = "Default Alerta authentication token"; - type = types.str; + type = lib.types.str; default = ""; }; - environment = mkOption { + environment = lib.mkOption { description = "Default Alerta environment"; - type = types.str; + type = lib.types.str; default = "Production"; }; - origin = mkOption { + origin = lib.mkOption { description = "Default origin of alert"; - type = types.str; + type = lib.types.str; default = "kapacitor"; }; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = [ pkgs.kapacitor ]; systemd.tmpfiles.settings."10-kapacitor".${cfg.dataDir}.d = { From 1e44f5e3df81545a4682a9a3192379abf52e9832 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:58 +0200 Subject: [PATCH 119/166] nixos/services.karma: remove `with lib;` --- nixos/modules/services/monitoring/karma.nix | 39 ++++++++++----------- 1 file changed, 19 insertions(+), 20 deletions(-) diff --git a/nixos/modules/services/monitoring/karma.nix b/nixos/modules/services/monitoring/karma.nix index b7ec5e4ae6fb..2300067719ff 100644 --- a/nixos/modules/services/monitoring/karma.nix +++ b/nixos/modules/services/monitoring/karma.nix @@ -1,17 +1,16 @@ { config, pkgs, lib, ... }: -with lib; let cfg = config.services.karma; yaml = pkgs.formats.yaml { }; in { options.services.karma = { - enable = mkEnableOption "the Karma dashboard service"; + enable = lib.mkEnableOption "the Karma dashboard service"; - package = mkPackageOption pkgs "karma" { }; + package = lib.mkPackageOption pkgs "karma" { }; - configFile = mkOption { - type = types.path; + configFile = lib.mkOption { + type = lib.types.path; default = yaml.generate "karma.yaml" cfg.settings; defaultText = "A configuration file generated from the provided nix attributes settings option."; description = '' @@ -20,8 +19,8 @@ in example = "/etc/karma/karma.conf"; }; - environment = mkOption { - type = with types; attrsOf str; + environment = lib.mkOption { + type = with lib.types; attrsOf str; default = {}; description = '' Additional environment variables to provide to karma. @@ -32,16 +31,16 @@ in }; }; - openFirewall = mkOption { - type = types.bool; + openFirewall = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether to open ports in the firewall needed for karma to function. ''; }; - extraOptions = mkOption { - type = with types; listOf str; + extraOptions = lib.mkOption { + type = with lib.types; listOf str; default = []; description = '' Extra command line options. @@ -51,13 +50,13 @@ in ]; }; - settings = mkOption { - type = types.submodule { + settings = lib.mkOption { + type = lib.types.submodule { freeformType = yaml.type; options.listen = { - address = mkOption { - type = types.str; + address = lib.mkOption { + type = lib.types.str; default = "127.0.0.1"; description = '' Hostname or IP to listen on. @@ -65,8 +64,8 @@ in example = "[::]"; }; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 8080; description = '' HTTP port to listen on. @@ -104,7 +103,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.karma = { description = "Alert dashboard for Prometheus Alertmanager"; wantedBy = [ "multi-user.target" ]; @@ -113,9 +112,9 @@ in Type = "simple"; DynamicUser = true; Restart = "on-failure"; - ExecStart = "${pkgs.karma}/bin/karma --config.file ${cfg.configFile} ${concatStringsSep " " cfg.extraOptions}"; + ExecStart = "${pkgs.karma}/bin/karma --config.file ${cfg.configFile} ${lib.concatStringsSep " " cfg.extraOptions}"; }; }; - networking.firewall.allowedTCPPorts = mkIf cfg.openFirewall [ cfg.settings.listen.port ]; + networking.firewall.allowedTCPPorts = lib.mkIf cfg.openFirewall [ cfg.settings.listen.port ]; }; } From 9353cb1b74283c9b0b8fa2ec7ed5862603d10bed Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:59 +0200 Subject: [PATCH 120/166] nixos/services.kthxbye: remove `with lib;` --- nixos/modules/services/monitoring/kthxbye.nix | 66 +++++++++---------- 1 file changed, 32 insertions(+), 34 deletions(-) diff --git a/nixos/modules/services/monitoring/kthxbye.nix b/nixos/modules/services/monitoring/kthxbye.nix index 81f47fba6679..a4ea97f0fa75 100644 --- a/nixos/modules/services/monitoring/kthxbye.nix +++ b/nixos/modules/services/monitoring/kthxbye.nix @@ -1,33 +1,31 @@ { config, pkgs, lib, ... }: -with lib; - let cfg = config.services.kthxbye; in { options.services.kthxbye = { - enable = mkEnableOption "kthxbye alert acknowledgement management daemon"; + enable = lib.mkEnableOption "kthxbye alert acknowledgement management daemon"; - package = mkPackageOption pkgs "kthxbye" { }; + package = lib.mkPackageOption pkgs "kthxbye" { }; - openFirewall = mkOption { - type = types.bool; + openFirewall = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether to open ports in the firewall needed for the daemon to function. ''; }; - extraOptions = mkOption { - type = with types; listOf str; + extraOptions = lib.mkOption { + type = with lib.types; listOf str; default = []; description = '' Extra command line options. Documentation can be found [here](https://github.com/prymitive/kthxbye/blob/main/README.md). ''; - example = literalExpression '' + example = lib.literalExpression '' [ "-extend-with-prefix 'ACK!'" ]; @@ -35,16 +33,16 @@ in }; alertmanager = { - timeout = mkOption { - type = types.str; + timeout = lib.mkOption { + type = lib.types.str; default = "1m0s"; description = '' Alertmanager request timeout duration in the [time.Duration](https://pkg.go.dev/time#ParseDuration) format. ''; example = "30s"; }; - uri = mkOption { - type = types.str; + uri = lib.mkOption { + type = lib.types.str; default = "http://localhost:9093"; description = '' Alertmanager URI to use. @@ -53,8 +51,8 @@ in }; }; - extendBy = mkOption { - type = types.str; + extendBy = lib.mkOption { + type = lib.types.str; default = "15m0s"; description = '' Extend silences by adding DURATION seconds. @@ -64,8 +62,8 @@ in example = "6h0m0s"; }; - extendIfExpiringIn = mkOption { - type = types.str; + extendIfExpiringIn = lib.mkOption { + type = lib.types.str; default = "5m0s"; description = '' Extend silences that are about to expire in the next DURATION seconds. @@ -75,8 +73,8 @@ in example = "1m0s"; }; - extendWithPrefix = mkOption { - type = types.str; + extendWithPrefix = lib.mkOption { + type = lib.types.str; default = "ACK!"; description = '' Extend silences with comment starting with PREFIX string. @@ -84,8 +82,8 @@ in example = "!perma-silence"; }; - interval = mkOption { - type = types.str; + interval = lib.mkOption { + type = lib.types.str; default = "45s"; description = '' Silence check interval duration in the [time.Duration](https://pkg.go.dev/time#ParseDuration) format. @@ -93,8 +91,8 @@ in example = "30s"; }; - listenAddress = mkOption { - type = types.str; + listenAddress = lib.mkOption { + type = lib.types.str; default = "0.0.0.0"; description = '' The address to listen on for HTTP requests. @@ -102,24 +100,24 @@ in example = "127.0.0.1"; }; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 8080; description = '' The port to listen on for HTTP requests. ''; }; - logJSON = mkOption { - type = types.bool; + logJSON = lib.mkOption { + type = lib.types.bool; default = false; description = '' Format logged messages as JSON. ''; }; - maxDuration = mkOption { - type = with types; nullOr str; + maxDuration = lib.mkOption { + type = with lib.types; nullOr str; default = null; description = '' Maximum duration of a silence, it won't be extended anymore after reaching it. @@ -130,7 +128,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.kthxbye = { description = "kthxbye Alertmanager ack management daemon"; wantedBy = [ "multi-user.target" ]; @@ -143,9 +141,9 @@ in -extend-with-prefix ${cfg.extendWithPrefix} \ -interval ${cfg.interval} \ -listen ${cfg.listenAddress}:${toString cfg.port} \ - ${optionalString cfg.logJSON "-log-json"} \ - ${optionalString (cfg.maxDuration != null) "-max-duration ${cfg.maxDuration}"} \ - ${concatStringsSep " " cfg.extraOptions} + ${lib.optionalString cfg.logJSON "-log-json"} \ + ${lib.optionalString (cfg.maxDuration != null) "-max-duration ${cfg.maxDuration}"} \ + ${lib.concatStringsSep " " cfg.extraOptions} ''; serviceConfig = { Type = "simple"; @@ -154,6 +152,6 @@ in }; }; - networking.firewall.allowedTCPPorts = mkIf cfg.openFirewall [ cfg.port ]; + networking.firewall.allowedTCPPorts = lib.mkIf cfg.openFirewall [ cfg.port ]; }; } From 56bd2c2da6d0d451bb1980980f26d7dac3bd1cb5 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:59 +0200 Subject: [PATCH 121/166] nixos/services.longview: remove `with lib;` --- .../modules/services/monitoring/longview.nix | 55 +++++++++---------- 1 file changed, 26 insertions(+), 29 deletions(-) diff --git a/nixos/modules/services/monitoring/longview.nix b/nixos/modules/services/monitoring/longview.nix index aafe54b994ab..ecb4836169db 100644 --- a/nixos/modules/services/monitoring/longview.nix +++ b/nixos/modules/services/monitoring/longview.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.longview; @@ -13,16 +10,16 @@ in { services.longview = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = '' If enabled, system metrics will be sent to Linode LongView. ''; }; - apiKey = mkOption { - type = types.str; + apiKey = lib.mkOption { + type = lib.types.str; default = ""; example = "01234567-89AB-CDEF-0123456789ABCDEF"; description = '' @@ -34,8 +31,8 @@ in { ''; }; - apiKeyFile = mkOption { - type = types.nullOr types.path; + apiKeyFile = lib.mkOption { + type = lib.types.nullOr lib.types.path; default = null; example = "/run/keys/longview-api-key"; description = '' @@ -47,8 +44,8 @@ in { ''; }; - apacheStatusUrl = mkOption { - type = types.str; + apacheStatusUrl = lib.mkOption { + type = lib.types.str; default = ""; example = "http://127.0.0.1/server-status"; description = '' @@ -58,8 +55,8 @@ in { ''; }; - nginxStatusUrl = mkOption { - type = types.str; + nginxStatusUrl = lib.mkOption { + type = lib.types.str; default = ""; example = "http://127.0.0.1/nginx_status"; description = '' @@ -69,8 +66,8 @@ in { ''; }; - mysqlUser = mkOption { - type = types.str; + mysqlUser = lib.mkOption { + type = lib.types.str; default = ""; description = '' The user for connecting to the MySQL database. If provided, @@ -80,8 +77,8 @@ in { ''; }; - mysqlPassword = mkOption { - type = types.str; + mysqlPassword = lib.mkOption { + type = lib.types.str; default = ""; description = '' The password corresponding to {option}`mysqlUser`. @@ -90,8 +87,8 @@ in { ''; }; - mysqlPasswordFile = mkOption { - type = types.nullOr types.path; + mysqlPasswordFile = lib.mkOption { + type = lib.types.nullOr lib.types.path; default = null; example = "/run/keys/dbpassword"; description = '' @@ -103,7 +100,7 @@ in { }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.longview = { description = "Longview Metrics Collection"; after = [ "network.target" ]; @@ -116,27 +113,27 @@ in { preStart = '' umask 077 mkdir -p ${configsDir} - '' + (optionalString (cfg.apiKeyFile != null) '' + '' + (lib.optionalString (cfg.apiKeyFile != null) '' cp --no-preserve=all "${cfg.apiKeyFile}" ${runDir}/longview.key - '') + (optionalString (cfg.apacheStatusUrl != "") '' + '') + (lib.optionalString (cfg.apacheStatusUrl != "") '' cat > ${configsDir}/Apache.conf < ${configsDir}/MySQL.conf < ${configsDir}/Nginx.conf < Date: Fri, 30 Aug 2024 00:46:59 +0200 Subject: [PATCH 122/166] nixos/services.mackerel-agent: remove `with lib;` --- .../services/monitoring/mackerel-agent.nix | 45 +++++++++---------- 1 file changed, 21 insertions(+), 24 deletions(-) diff --git a/nixos/modules/services/monitoring/mackerel-agent.nix b/nixos/modules/services/monitoring/mackerel-agent.nix index 0908ea9ca68e..4d2d2e6c5972 100644 --- a/nixos/modules/services/monitoring/mackerel-agent.nix +++ b/nixos/modules/services/monitoring/mackerel-agent.nix @@ -1,24 +1,21 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.mackerel-agent; settingsFmt = pkgs.formats.toml {}; in { options.services.mackerel-agent = { - enable = mkEnableOption "mackerel.io agent"; + enable = lib.mkEnableOption "mackerel.io agent"; # the upstream package runs as root, but doesn't seem to be strictly # necessary for basic functionality - runAsRoot = mkEnableOption "running as root"; + runAsRoot = lib.mkEnableOption "running as root"; - autoRetirement = mkEnableOption '' + autoRetirement = lib.mkEnableOption '' retiring the host upon OS shutdown ''; - apiKeyFile = mkOption { - type = types.path; + apiKeyFile = lib.mkOption { + type = lib.types.path; example = "/run/keys/mackerel-api-key"; description = '' Path to file containing the Mackerel API key. The file should contain a @@ -28,7 +25,7 @@ in { ''; }; - settings = mkOption { + settings = lib.mkOption { description = '' Options for mackerel-agent.conf. @@ -42,29 +39,29 @@ in { silent = false; }; - type = types.submodule { + type = lib.types.submodule { freeformType = settingsFmt.type; options.host_status = { - on_start = mkOption { - type = types.enum [ "working" "standby" "maintenance" "poweroff" ]; + on_start = lib.mkOption { + type = lib.types.enum [ "working" "standby" "maintenance" "poweroff" ]; description = "Host status after agent startup."; default = "working"; }; - on_stop = mkOption { - type = types.enum [ "working" "standby" "maintenance" "poweroff" ]; + on_stop = lib.mkOption { + type = lib.types.enum [ "working" "standby" "maintenance" "poweroff" ]; description = "Host status after agent shutdown."; default = "poweroff"; }; }; options.diagnostic = - mkEnableOption "collecting memory usage for the agent itself"; + lib.mkEnableOption "collecting memory usage for the agent itself"; }; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = with pkgs; [ mackerel-agent ]; environment.etc = { @@ -74,11 +71,11 @@ in { }; services.mackerel-agent.settings = { - root = mkDefault "/var/lib/mackerel-agent"; - pidfile = mkDefault "/run/mackerel-agent/mackerel-agent.pid"; + root = lib.mkDefault "/var/lib/mackerel-agent"; + pidfile = lib.mkDefault "/run/mackerel-agent/mackerel-agent.pid"; # conf.d stores the symlink to cfg.apiKeyFile - include = mkDefault "/etc/mackerel-agent/conf.d/*.conf"; + include = lib.mkDefault "/etc/mackerel-agent/conf.d/*.conf"; }; # upstream service file in https://github.com/mackerelio/mackerel-agent/blob/master/packaging/rpm/src/mackerel-agent.service @@ -88,20 +85,20 @@ in { after = [ "network-online.target" "nss-lookup.target" ]; wantedBy = [ "multi-user.target" ]; environment = { - MACKEREL_PLUGIN_WORKDIR = mkDefault "%C/mackerel-agent"; + MACKEREL_PLUGIN_WORKDIR = lib.mkDefault "%C/mackerel-agent"; }; serviceConfig = { DynamicUser = !cfg.runAsRoot; - PrivateTmp = mkDefault true; + PrivateTmp = lib.mkDefault true; CacheDirectory = "mackerel-agent"; ConfigurationDirectory = "mackerel-agent"; RuntimeDirectory = "mackerel-agent"; StateDirectory = "mackerel-agent"; ExecStart = "${pkgs.mackerel-agent}/bin/mackerel-agent supervise"; - ExecStopPost = mkIf cfg.autoRetirement "${pkgs.mackerel-agent}/bin/mackerel-agent retire -force"; + ExecStopPost = lib.mkIf cfg.autoRetirement "${pkgs.mackerel-agent}/bin/mackerel-agent retire -force"; ExecReload = "${pkgs.coreutils}/bin/kill -HUP $MAINPID"; - LimitNOFILE = mkDefault 65536; - LimitNPROC = mkDefault 65536; + LimitNOFILE = lib.mkDefault 65536; + LimitNPROC = lib.mkDefault 65536; }; restartTriggers = [ config.environment.etc."mackerel-agent/mackerel-agent.conf".source From faf7fde49ebd389bd51b10666e667bee04ad5aa4 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:59 +0200 Subject: [PATCH 123/166] nixos/services.monit: remove `with lib;` --- nixos/modules/services/monitoring/monit.nix | 13 +++++-------- 1 file changed, 5 insertions(+), 8 deletions(-) diff --git a/nixos/modules/services/monitoring/monit.nix b/nixos/modules/services/monitoring/monit.nix index 379ee967620e..3fa4e178b113 100644 --- a/nixos/modules/services/monitoring/monit.nix +++ b/nixos/modules/services/monitoring/monit.nix @@ -1,7 +1,4 @@ {config, pkgs, lib, ...}: - -with lib; - let cfg = config.services.monit; in @@ -9,17 +6,17 @@ in { options.services.monit = { - enable = mkEnableOption "Monit"; + enable = lib.mkEnableOption "Monit"; - config = mkOption { - type = types.lines; + config = lib.mkOption { + type = lib.types.lines; default = ""; description = "monitrc content"; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = [ pkgs.monit ]; @@ -44,5 +41,5 @@ in }; - meta.maintainers = with maintainers; [ ryantm ]; + meta.maintainers = with lib.maintainers; [ ryantm ]; } From 34970fdcf3b5877b8d8c7248040333276a53607a Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:46:59 +0200 Subject: [PATCH 124/166] nixos/services.munin-[cron,node]: remove `with lib;` --- nixos/modules/services/monitoring/munin.nix | 58 +++++++++------------ 1 file changed, 26 insertions(+), 32 deletions(-) diff --git a/nixos/modules/services/monitoring/munin.nix b/nixos/modules/services/monitoring/munin.nix index 401f6383cb57..91a000ade87b 100644 --- a/nixos/modules/services/monitoring/munin.nix +++ b/nixos/modules/services/monitoring/munin.nix @@ -1,18 +1,12 @@ { config, lib, pkgs, ... }: - # TODO: support munin-async # TODO: LWP/Pg perl libs aren't recognized - # TODO: support fastcgi # https://guide.munin-monitoring.org/en/latest/example/webserver/apache-cgi.html # spawn-fcgi -s /run/munin/fastcgi-graph.sock -U www-data -u munin -g munin /usr/lib/munin/cgi/munin-cgi-graph # spawn-fcgi -s /run/munin/fastcgi-html.sock -U www-data -u munin -g munin /usr/lib/munin/cgi/munin-cgi-html # https://paste.sh/vofcctHP#-KbDSXVeWoifYncZmLfZzgum # nginx https://munin.readthedocs.org/en/latest/example/webserver/nginx.html - - -with lib; - let nodeCfg = config.services.munin-node; cronCfg = config.services.munin-cron; @@ -140,9 +134,9 @@ in services.munin-node = { - enable = mkOption { + enable = lib.mkOption { default = false; - type = types.bool; + type = lib.types.bool; description = '' Enable Munin Node agent. Munin node listens on 0.0.0.0 and by default accepts connections only from 127.0.0.1 for security reasons. @@ -151,18 +145,18 @@ in ''; }; - extraConfig = mkOption { + extraConfig = lib.mkOption { default = ""; - type = types.lines; + type = lib.types.lines; description = '' {file}`munin-node.conf` extra configuration. See ''; }; - extraPluginConfig = mkOption { + extraPluginConfig = lib.mkOption { default = ""; - type = types.lines; + type = lib.types.lines; description = '' {file}`plugin-conf.d` extra plugin configuration. See @@ -173,9 +167,9 @@ in ''; }; - extraPlugins = mkOption { + extraPlugins = lib.mkOption { default = {}; - type = with types; attrsOf path; + type = with lib.types; attrsOf path; description = '' Additional Munin plugins to activate. Keys are the name of the plugin symlink, values are the path to the underlying plugin script. You @@ -194,7 +188,7 @@ in `/bin`, `/usr/bin`, `/sbin`, and `/usr/sbin`. ''; - example = literalExpression '' + example = lib.literalExpression '' { zfs_usage_bigpool = /src/munin-contrib/plugins/zfs/zfs_usage_; zfs_usage_smallpool = /src/munin-contrib/plugins/zfs/zfs_usage_; @@ -203,9 +197,9 @@ in ''; }; - extraAutoPlugins = mkOption { + extraAutoPlugins = lib.mkOption { default = []; - type = with types; listOf path; + type = with lib.types; listOf path; description = '' Additional Munin plugins to autoconfigure, using `munin-node-configure --suggest`. These should be @@ -225,7 +219,7 @@ in `/bin`, `/usr/bin`, `/sbin`, and `/usr/sbin`. ''; - example = literalExpression '' + example = lib.literalExpression '' [ /src/munin-contrib/plugins/zfs /src/munin-contrib/plugins/ssh @@ -233,12 +227,12 @@ in ''; }; - disabledPlugins = mkOption { + disabledPlugins = lib.mkOption { # TODO: figure out why Munin isn't writing the log file and fix it. # In the meantime this at least suppresses a useless graph full of # NaNs in the output. default = [ "munin_stats" ]; - type = with types; listOf str; + type = with lib.types; listOf str; description = '' Munin plugins to disable, even if `munin-node-configure --suggest` tries to enable @@ -255,9 +249,9 @@ in services.munin-cron = { - enable = mkOption { + enable = lib.mkOption { default = false; - type = types.bool; + type = lib.types.bool; description = '' Enable munin-cron. Takes care of all heavy lifting to collect data from nodes and draws graphs to html. Runs munin-update, munin-limits, @@ -268,9 +262,9 @@ in ''; }; - extraGlobalConfig = mkOption { + extraGlobalConfig = lib.mkOption { default = ""; - type = types.lines; + type = lib.types.lines; description = '' {file}`munin.conf` extra global configuration. See . @@ -282,15 +276,15 @@ in ''; }; - hosts = mkOption { + hosts = lib.mkOption { default = ""; - type = types.lines; + type = lib.types.lines; description = '' Definitions of hosts of nodes to collect data from. Needs at least one host for cron to succeed. See ''; - example = literalExpression '' + example = lib.literalExpression '' ''' [''${config.networking.hostName}] address localhost @@ -298,9 +292,9 @@ in ''; }; - extraCSS = mkOption { + extraCSS = lib.mkOption { default = ""; - type = types.lines; + type = lib.types.lines; description = '' Custom styling for the HTML that munin-cron generates. This will be appended to the CSS files used by munin-cron and will thus take @@ -320,7 +314,7 @@ in }; - config = mkMerge [ (mkIf (nodeCfg.enable || cronCfg.enable) { + config = lib.mkMerge [ (lib.mkIf (nodeCfg.enable || cronCfg.enable) { environment.systemPackages = [ pkgs.munin ]; @@ -335,7 +329,7 @@ in gid = config.ids.gids.munin; }; - }) (mkIf nodeCfg.enable { + }) (lib.mkIf nodeCfg.enable { systemd.services.munin-node = { description = "Munin Node"; @@ -380,7 +374,7 @@ in group = "munin"; }; - }) (mkIf cronCfg.enable { + }) (lib.mkIf cronCfg.enable { # Munin is hardcoded to use DejaVu Mono and the graphs come out wrong if # it's not available. From c93d8f88a71945030334b2fd29858c09b51fc2b3 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:00 +0200 Subject: [PATCH 125/166] nixos/services.nagios: remove `with lib;` --- nixos/modules/services/monitoring/nagios.nix | 59 ++++++++++---------- 1 file changed, 28 insertions(+), 31 deletions(-) diff --git a/nixos/modules/services/monitoring/nagios.nix b/nixos/modules/services/monitoring/nagios.nix index e475d41270b1..b8bb4cae8a06 100644 --- a/nixos/modules/services/monitoring/nagios.nix +++ b/nixos/modules/services/monitoring/nagios.nix @@ -1,8 +1,5 @@ # Nagios system/network monitoring daemon. { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.nagios; @@ -35,8 +32,8 @@ let illegal_macro_output_chars="`~$&|'\"<>"; retain_state_information="1"; }; - lines = mapAttrsToList (key: value: "${key}=${value}") (default // cfg.extraConfig); - content = concatStringsSep "\n" lines; + lines = lib.mapAttrsToList (key: value: "${key}=${value}") (default // cfg.extraConfig); + content = lib.concatStringsSep "\n" lines; file = pkgs.writeText "nagios.cfg" content; validated = pkgs.runCommand "nagios-checked.cfg" {preferLocalBuild=true;} '' cp ${file} nagios.cfg @@ -81,45 +78,45 @@ let in { imports = [ - (mkRemovedOptionModule [ "services" "nagios" "urlPath" ] "The urlPath option has been removed as it is hard coded to /nagios in the nagios package.") + (lib.mkRemovedOptionModule [ "services" "nagios" "urlPath" ] "The urlPath option has been removed as it is hard coded to /nagios in the nagios package.") ]; meta.maintainers = with lib.maintainers; [ symphorien ]; options = { services.nagios = { - enable = mkEnableOption ''[Nagios](https://www.nagios.org/) to monitor your system or network''; + enable = lib.mkEnableOption ''[Nagios](https://www.nagios.org/) to monitor your system or network''; - objectDefs = mkOption { + objectDefs = lib.mkOption { description = '' A list of Nagios object configuration files that must define the hosts, host groups, services and contacts for the network that you want Nagios to monitor. ''; - type = types.listOf types.path; - example = literalExpression "[ ./objects.cfg ]"; + type = lib.types.listOf lib.types.path; + example = lib.literalExpression "[ ./objects.cfg ]"; }; - plugins = mkOption { - type = types.listOf types.package; + plugins = lib.mkOption { + type = lib.types.listOf lib.types.package; default = with pkgs; [ monitoring-plugins msmtp mailutils ]; - defaultText = literalExpression "[pkgs.monitoring-plugins pkgs.msmtp pkgs.mailutils]"; + defaultText = lib.literalExpression "[pkgs.monitoring-plugins pkgs.msmtp pkgs.mailutils]"; description = '' Packages to be added to the Nagios {env}`PATH`. Typically used to add plugins, but can be anything. ''; }; - mainConfigFile = mkOption { - type = types.nullOr types.package; + mainConfigFile = lib.mkOption { + type = lib.types.nullOr lib.types.package; default = null; description = '' If non-null, overrides the main configuration file of Nagios. ''; }; - extraConfig = mkOption { - type = types.attrsOf types.str; + extraConfig = lib.mkOption { + type = lib.types.attrsOf lib.types.str; example = { debug_level = "-1"; debug_file = "/var/log/nagios/debug.log"; @@ -128,25 +125,25 @@ in description = "Configuration to add to /etc/nagios.cfg"; }; - validateConfig = mkOption { - type = types.bool; + validateConfig = lib.mkOption { + type = lib.types.bool; default = pkgs.stdenv.hostPlatform == pkgs.stdenv.buildPlatform; - defaultText = literalExpression "pkgs.stdenv.hostPlatform == pkgs.stdenv.buildPlatform"; + defaultText = lib.literalExpression "pkgs.stdenv.hostPlatform == pkgs.stdenv.buildPlatform"; description = "if true, the syntax of the nagios configuration file is checked at build time"; }; - cgiConfigFile = mkOption { - type = types.package; + cgiConfigFile = lib.mkOption { + type = lib.types.package; default = nagiosCGICfgFile; - defaultText = literalExpression "nagiosCGICfgFile"; + defaultText = lib.literalExpression "nagiosCGICfgFile"; description = '' Derivation for the configuration file of Nagios CGI scripts that can be used in web servers for running the Nagios web interface. ''; }; - enableWebInterface = mkOption { - type = types.bool; + enableWebInterface = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether to enable the Nagios web interface. You should also @@ -154,9 +151,9 @@ in ''; }; - virtualHost = mkOption { - type = types.submodule (import ../web-servers/apache-httpd/vhost-options.nix); - example = literalExpression '' + virtualHost = lib.mkOption { + type = lib.types.submodule (import ../web-servers/apache-httpd/vhost-options.nix); + example = lib.literalExpression '' { hostName = "example.org"; adminAddr = "webmaster@example.org"; enableSSL = true; @@ -173,7 +170,7 @@ in }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { users.users.nagios = { description = "Nagios user"; uid = config.ids.uids.nagios; @@ -206,8 +203,8 @@ in }; }; - services.httpd.virtualHosts = optionalAttrs cfg.enableWebInterface { - ${cfg.virtualHost.hostName} = mkMerge [ cfg.virtualHost { extraConfig = extraHttpdConfig; } ]; + services.httpd.virtualHosts = lib.optionalAttrs cfg.enableWebInterface { + ${cfg.virtualHost.hostName} = lib.mkMerge [ cfg.virtualHost { extraConfig = extraHttpdConfig; } ]; }; }; } From f88528a137bee03be97021fbe857889a6b5a28be Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:00 +0200 Subject: [PATCH 126/166] nixos/services.netdata: remove `with lib;` --- nixos/modules/services/monitoring/netdata.nix | 83 +++++++++---------- 1 file changed, 40 insertions(+), 43 deletions(-) diff --git a/nixos/modules/services/monitoring/netdata.nix b/nixos/modules/services/monitoring/netdata.nix index 6e18ef562b8f..cbcfc2d008d5 100644 --- a/nixos/modules/services/monitoring/netdata.nix +++ b/nixos/modules/services/monitoring/netdata.nix @@ -1,7 +1,4 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.services.netdata; @@ -25,7 +22,7 @@ let configDirectory = pkgs.runCommand "netdata-config-d" { } '' mkdir $out - ${concatStringsSep "\n" (mapAttrsToList (path: file: '' + ${lib.concatStringsSep "\n" (lib.mapAttrsToList (path: file: '' mkdir -p "$out/$(dirname ${path})" ln -s "${file}" "$out/${path}" '') cfg.configDir)} @@ -34,7 +31,7 @@ let localConfig = { global = { "config directory" = "/etc/netdata/conf.d"; - "plugins directory" = concatStringsSep " " plugins; + "plugins directory" = lib.concatStringsSep " " plugins; }; web = { "web files owner" = "root"; @@ -45,7 +42,7 @@ let "use unified cgroups" = "yes"; }; }; - mkConfig = generators.toINI {} (recursiveUpdate localConfig cfg.config); + mkConfig = lib.generators.toINI {} (lib.recursiveUpdate localConfig cfg.config); configFile = pkgs.writeText "netdata.conf" (if cfg.configText != null then cfg.configText else mkConfig); defaultUser = "netdata"; @@ -54,24 +51,24 @@ let in { options = { services.netdata = { - enable = mkEnableOption "netdata"; + enable = lib.mkEnableOption "netdata"; - package = mkPackageOption pkgs "netdata" { }; + package = lib.mkPackageOption pkgs "netdata" { }; - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; default = "netdata"; description = "User account under which netdata runs."; }; - group = mkOption { - type = types.str; + group = lib.mkOption { + type = lib.types.str; default = "netdata"; description = "Group under which netdata runs."; }; - configText = mkOption { - type = types.nullOr types.lines; + configText = lib.mkOption { + type = lib.types.nullOr lib.types.lines; description = "Verbatim netdata.conf, cannot be combined with config."; default = null; example = '' @@ -83,26 +80,26 @@ in { }; python = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = true; description = '' Whether to enable python-based plugins ''; }; - recommendedPythonPackages = mkOption { - type = types.bool; + recommendedPythonPackages = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether to enable a set of recommended Python plugins by installing extra Python packages. ''; }; - extraPackages = mkOption { - type = types.functionTo (types.listOf types.package); + extraPackages = lib.mkOption { + type = lib.types.functionTo (lib.types.listOf lib.types.package); default = ps: []; - defaultText = literalExpression "ps: []"; - example = literalExpression '' + defaultText = lib.literalExpression "ps: []"; + example = lib.literalExpression '' ps: [ ps.psycopg2 ps.docker @@ -116,10 +113,10 @@ in { }; }; - extraPluginPaths = mkOption { - type = types.listOf types.path; + extraPluginPaths = lib.mkOption { + type = lib.types.listOf lib.types.path; default = [ ]; - example = literalExpression '' + example = lib.literalExpression '' [ "/path/to/plugins.d" ] ''; description = '' @@ -134,11 +131,11 @@ in { ''; }; - config = mkOption { - type = types.attrsOf types.attrs; + config = lib.mkOption { + type = lib.types.attrsOf lib.types.attrs; default = {}; description = "netdata.conf configuration as nix attributes. cannot be combined with configText."; - example = literalExpression '' + example = lib.literalExpression '' global = { "debug log" = "syslog"; "access log" = "syslog"; @@ -147,8 +144,8 @@ in { ''; }; - configDir = mkOption { - type = types.attrsOf types.path; + configDir = lib.mkOption { + type = lib.types.attrsOf lib.types.path; default = {}; description = '' Complete netdata config directory except netdata.conf. @@ -159,7 +156,7 @@ in { Its value is the absolute path and must be readable by netdata. Cannot be combined with configText. ''; - example = literalExpression '' + example = lib.literalExpression '' "health_alarm_notify.conf" = pkgs.writeText "health_alarm_notify.conf" ''' sendmail="/path/to/sendmail" '''; @@ -167,8 +164,8 @@ in { ''; }; - claimTokenFile = mkOption { - type = types.nullOr types.path; + claimTokenFile = lib.mkOption { + type = lib.types.nullOr lib.types.path; default = null; description = '' If set, automatically registers the agent using the given claim token @@ -176,8 +173,8 @@ in { ''; }; - enableAnalyticsReporting = mkOption { - type = types.bool; + enableAnalyticsReporting = lib.mkOption { + type = lib.types.bool; default = false; description = '' Enable reporting of anonymous usage statistics to Netdata Inc. via either @@ -187,8 +184,8 @@ in { ''; }; - deadlineBeforeStopSec = mkOption { - type = types.int; + deadlineBeforeStopSec = lib.mkOption { + type = lib.types.int; default = 120; description = '' In order to detect when netdata is misbehaving, we run a concurrent task pinging netdata (wait-for-netdata-up) @@ -203,7 +200,7 @@ in { }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { assertions = [ { assertion = cfg.config != {} -> cfg.configText == null ; message = "Cannot specify both config and configText"; @@ -220,7 +217,7 @@ in { ps.netdata-pandas ]); - services.netdata.configDir.".opt-out-from-anonymous-statistics" = mkIf (!cfg.enableAnalyticsReporting) (pkgs.writeText ".opt-out-from-anonymous-statistics" ""); + services.netdata.configDir.".opt-out-from-anonymous-statistics" = lib.mkIf (!cfg.enableAnalyticsReporting) (pkgs.writeText ".opt-out-from-anonymous-statistics" ""); environment.etc."netdata/netdata.conf".source = configFile; environment.etc."netdata/conf.d".source = configDirectory; @@ -381,7 +378,7 @@ in { permissions = "u+rx,g+x,o-rwx"; }; - } // optionalAttrs (cfg.package.withIpmi) { + } // lib.optionalAttrs (cfg.package.withIpmi) { "freeipmi.plugin" = { source = "${cfg.package}/libexec/netdata/plugins.d/freeipmi.plugin.org"; capabilities = "cap_dac_override,cap_fowner+ep"; @@ -389,7 +386,7 @@ in { group = cfg.group; permissions = "u+rx,g+x,o-rwx"; }; - } // optionalAttrs (cfg.package.withNetworkViewer) { + } // lib.optionalAttrs (cfg.package.withNetworkViewer) { "network-viewer.plugin" = { source = "${cfg.package}/libexec/netdata/plugins.d/network-viewer.plugin.org"; capabilities = "cap_sys_admin,cap_dac_read_search,cap_sys_ptrace+ep"; @@ -404,7 +401,7 @@ in { { domain = "netdata"; type = "hard"; item = "nofile"; value = "30000"; } ]; - users.users = optionalAttrs (cfg.user == defaultUser) { + users.users = lib.optionalAttrs (cfg.user == defaultUser) { ${defaultUser} = { group = defaultUser; isSystemUser = true; @@ -413,7 +410,7 @@ in { }; }; - users.groups = optionalAttrs (cfg.group == defaultUser) { + users.groups = lib.optionalAttrs (cfg.group == defaultUser) { ${defaultUser} = { }; }; From 500c84cedd93edee492e54452922cc354ab5b9ef Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:00 +0200 Subject: [PATCH 127/166] nixos/services.osquery: remove `with lib;` --- nixos/modules/services/monitoring/osquery.nix | 24 +++++++++---------- 1 file changed, 11 insertions(+), 13 deletions(-) diff --git a/nixos/modules/services/monitoring/osquery.nix b/nixos/modules/services/monitoring/osquery.nix index 872f5e96a412..8f728ebab115 100644 --- a/nixos/modules/services/monitoring/osquery.nix +++ b/nixos/modules/services/monitoring/osquery.nix @@ -1,6 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; let cfg = config.services.osquery; dirname = path: with lib.strings; with lib.lists; concatStringsSep "/" @@ -13,8 +11,8 @@ let # flagfile is the file containing osquery command line flags to be # provided to the application using the special --flagfile option. flagfile = pkgs.writeText "osquery.flags" - (concatStringsSep "\n" - (mapAttrsToList (name: value: "--${name}=${value}") + (lib.concatStringsSep "\n" + (lib.mapAttrsToList (name: value: "--${name}=${value}") # Use the conf derivation if not otherwise specified. ({ config_path = conf; } // cfg.flags))); @@ -26,9 +24,9 @@ let in { options.services.osquery = { - enable = mkEnableOption "osqueryd daemon"; + enable = lib.mkEnableOption "osqueryd daemon"; - settings = mkOption { + settings = lib.mkOption { default = { }; description = '' Configuration to be written to the osqueryd JSON configuration file. @@ -37,10 +35,10 @@ in example = { options.utc = false; }; - type = types.attrs; + type = lib.types.attrs; }; - flags = mkOption { + flags = lib.mkOption { default = { }; description = '' Attribute set of flag names and values to be written to the osqueryd flagfile. @@ -49,23 +47,23 @@ in example = { config_refresh = "10"; }; - type = with types; + type = with lib.types; submodule { freeformType = attrsOf str; options = { - database_path = mkOption { + database_path = lib.mkOption { default = "/var/lib/osquery/osquery.db"; readOnly = true; description = "Path used for the database file."; type = path; }; - logger_path = mkOption { + logger_path = lib.mkOption { default = "/var/log/osquery"; readOnly = true; description = "Base directory used for logging."; type = path; }; - pidfile = mkOption { + pidfile = lib.mkOption { default = "/run/osquery/osqueryd.pid"; readOnly = true; description = "Path used for pid file."; @@ -76,7 +74,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = [ osqueryi ]; systemd.services.osqueryd = { after = [ "network.target" "syslog.service" ]; From c617a4cb83f251fb8753e51ee11b42aaaafb9489 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:00 +0200 Subject: [PATCH 128/166] nixos/services.prometheus.alertmanagerIrcRelay: remove `with lib;` --- .../prometheus/alertmanager-irc-relay.nix | 21 ++++++++----------- 1 file changed, 9 insertions(+), 12 deletions(-) diff --git a/nixos/modules/services/monitoring/prometheus/alertmanager-irc-relay.nix b/nixos/modules/services/monitoring/prometheus/alertmanager-irc-relay.nix index eda4277c1bac..4995663ed7ca 100644 --- a/nixos/modules/services/monitoring/prometheus/alertmanager-irc-relay.nix +++ b/nixos/modules/services/monitoring/prometheus/alertmanager-irc-relay.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.prometheus.alertmanagerIrcRelay; @@ -10,19 +7,19 @@ let in { options.services.prometheus.alertmanagerIrcRelay = { - enable = mkEnableOption "Alertmanager IRC Relay"; + enable = lib.mkEnableOption "Alertmanager IRC Relay"; - package = mkPackageOption pkgs "alertmanager-irc-relay" { }; + package = lib.mkPackageOption pkgs "alertmanager-irc-relay" { }; - extraFlags = mkOption { - type = types.listOf types.str; + extraFlags = lib.mkOption { + type = lib.types.listOf lib.types.str; default = []; description = "Extra command line options to pass to alertmanager-irc-relay."; }; - settings = mkOption { + settings = lib.mkOption { type = configFormat.type; - example = literalExpression '' + example = lib.literalExpression '' { http_host = "localhost"; http_port = 8000; @@ -50,7 +47,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.alertmanager-irc-relay = { description = "Alertmanager IRC Relay"; @@ -61,7 +58,7 @@ in ExecStart = '' ${cfg.package}/bin/alertmanager-irc-relay \ -config ${configFile} \ - ${escapeShellArgs cfg.extraFlags} + ${lib.escapeShellArgs cfg.extraFlags} ''; DynamicUser = true; @@ -98,5 +95,5 @@ in }; }; - meta.maintainers = [ maintainers.oxzi ]; + meta.maintainers = [ lib.maintainers.oxzi ]; } From 951787fba30b6e4a94d9262fdc6f4751a2a41af6 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:01 +0200 Subject: [PATCH 129/166] nixos/services.prometheus.alertmanagerWebhookLogger: remove `with lib;` --- .../prometheus/alertmanager-webhook-logger.nix | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-) diff --git a/nixos/modules/services/monitoring/prometheus/alertmanager-webhook-logger.nix b/nixos/modules/services/monitoring/prometheus/alertmanager-webhook-logger.nix index b3665b66ba40..1761e6305107 100644 --- a/nixos/modules/services/monitoring/prometheus/alertmanager-webhook-logger.nix +++ b/nixos/modules/services/monitoring/prometheus/alertmanager-webhook-logger.nix @@ -1,24 +1,21 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.prometheus.alertmanagerWebhookLogger; in { options.services.prometheus.alertmanagerWebhookLogger = { - enable = mkEnableOption "Alertmanager Webhook Logger"; + enable = lib.mkEnableOption "Alertmanager Webhook Logger"; - package = mkPackageOption pkgs "alertmanager-webhook-logger" { }; + package = lib.mkPackageOption pkgs "alertmanager-webhook-logger" { }; - extraFlags = mkOption { - type = types.listOf types.str; + extraFlags = lib.mkOption { + type = lib.types.listOf lib.types.str; default = []; description = "Extra command line options to pass to alertmanager-webhook-logger."; }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.alertmanager-webhook-logger = { description = "Alertmanager Webhook Logger"; @@ -29,7 +26,7 @@ in serviceConfig = { ExecStart = '' ${cfg.package}/bin/alertmanager-webhook-logger \ - ${escapeShellArgs cfg.extraFlags} + ${lib.escapeShellArgs cfg.extraFlags} ''; CapabilityBoundingSet = [ "" ]; @@ -77,5 +74,5 @@ in }; }; - meta.maintainers = [ maintainers.jpds ]; + meta.maintainers = [ lib.maintainers.jpds ]; } From ea4bd5327457e785d9e986c61eccaefd853b0545 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:01 +0200 Subject: [PATCH 130/166] nixos/services.prometheus.alertmanager: remove `with lib;` --- .../monitoring/prometheus/alertmanager.nix | 79 +++++++++---------- 1 file changed, 38 insertions(+), 41 deletions(-) diff --git a/nixos/modules/services/monitoring/prometheus/alertmanager.nix b/nixos/modules/services/monitoring/prometheus/alertmanager.nix index 7e53ca04cb39..70bd07c59820 100644 --- a/nixos/modules/services/monitoring/prometheus/alertmanager.nix +++ b/nixos/modules/services/monitoring/prometheus/alertmanager.nix @@ -1,7 +1,4 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.services.prometheus.alertmanager; mkConfigFile = pkgs.writeText "alertmanager.yml" (builtins.toJSON cfg.configuration); @@ -25,16 +22,16 @@ let "--log.level ${cfg.logLevel}" "--storage.path /var/lib/alertmanager" (toString (map (peer: "--cluster.peer ${peer}:9094") cfg.clusterPeers)) - ] ++ (optional (cfg.webExternalUrl != null) + ] ++ (lib.optional (cfg.webExternalUrl != null) "--web.external-url ${cfg.webExternalUrl}" - ) ++ (optional (cfg.logFormat != null) + ) ++ (lib.optional (cfg.logFormat != null) "--log.format ${cfg.logFormat}" ); in { imports = [ - (mkRemovedOptionModule [ "services" "prometheus" "alertmanager" "user" ] "The alertmanager service is now using systemd's DynamicUser mechanism which obviates a user setting.") - (mkRemovedOptionModule [ "services" "prometheus" "alertmanager" "group" ] "The alertmanager service is now using systemd's DynamicUser mechanism which obviates a group setting.") - (mkRemovedOptionModule [ "services" "prometheus" "alertmanagerURL" ] '' + (lib.mkRemovedOptionModule [ "services" "prometheus" "alertmanager" "user" ] "The alertmanager service is now using systemd's DynamicUser mechanism which obviates a user setting.") + (lib.mkRemovedOptionModule [ "services" "prometheus" "alertmanager" "group" ] "The alertmanager service is now using systemd's DynamicUser mechanism which obviates a group setting.") + (lib.mkRemovedOptionModule [ "services" "prometheus" "alertmanagerURL" ] '' Due to incompatibility, the alertmanagerURL option has been removed, please use 'services.prometheus.alertmanagers' instead. '') @@ -42,12 +39,12 @@ in { options = { services.prometheus.alertmanager = { - enable = mkEnableOption "Prometheus Alertmanager"; + enable = lib.mkEnableOption "Prometheus Alertmanager"; - package = mkPackageOption pkgs "prometheus-alertmanager" { }; + package = lib.mkPackageOption pkgs "prometheus-alertmanager" { }; - configuration = mkOption { - type = types.nullOr types.attrs; + configuration = lib.mkOption { + type = lib.types.nullOr lib.types.attrs; default = null; description = '' Alertmanager configuration as nix attribute set. @@ -57,8 +54,8 @@ in { ''; }; - configText = mkOption { - type = types.nullOr types.lines; + configText = lib.mkOption { + type = lib.types.nullOr lib.types.lines; default = null; description = '' Alertmanager configuration as YAML text. If non-null, this option @@ -71,8 +68,8 @@ in { ''; }; - checkConfig = mkOption { - type = types.bool; + checkConfig = lib.mkOption { + type = lib.types.bool; default = true; description = '' Check configuration with `amtool check-config`. The call to `amtool` is @@ -85,24 +82,24 @@ in { ''; }; - logFormat = mkOption { - type = types.nullOr types.str; + logFormat = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; description = '' If set use a syslog logger or JSON logging. ''; }; - logLevel = mkOption { - type = types.enum ["debug" "info" "warn" "error" "fatal"]; + logLevel = lib.mkOption { + type = lib.types.enum ["debug" "info" "warn" "error" "fatal"]; default = "warn"; description = '' Only log messages with the given severity or above. ''; }; - webExternalUrl = mkOption { - type = types.nullOr types.str; + webExternalUrl = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; description = '' The URL under which Alertmanager is externally reachable (for example, if Alertmanager is served via a reverse proxy). @@ -112,8 +109,8 @@ in { ''; }; - listenAddress = mkOption { - type = types.str; + listenAddress = lib.mkOption { + type = lib.types.str; default = ""; description = '' Address to listen on for the web interface and API. Empty string will listen on all interfaces. @@ -121,40 +118,40 @@ in { ''; }; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 9093; description = '' Port to listen on for the web interface and API. ''; }; - openFirewall = mkOption { - type = types.bool; + openFirewall = lib.mkOption { + type = lib.types.bool; default = false; description = '' Open port in firewall for incoming connections. ''; }; - clusterPeers = mkOption { - type = types.listOf types.str; + clusterPeers = lib.mkOption { + type = lib.types.listOf lib.types.str; default = []; description = '' Initial peers for HA cluster. ''; }; - extraFlags = mkOption { - type = types.listOf types.str; + extraFlags = lib.mkOption { + type = lib.types.listOf lib.types.str; default = []; description = '' Extra commandline options when launching the Alertmanager. ''; }; - environmentFile = mkOption { - type = types.nullOr types.path; + environmentFile = lib.mkOption { + type = lib.types.nullOr lib.types.path; default = null; example = "/root/alertmanager.env"; description = '' @@ -167,16 +164,16 @@ in { }; }; - config = mkMerge [ - (mkIf cfg.enable { - assertions = singleton { + config = lib.mkMerge [ + (lib.mkIf cfg.enable { + assertions = lib.singleton { assertion = cfg.configuration != null || cfg.configText != null; message = "Can not enable alertmanager without a configuration. " + "Set either the `configuration` or `configText` attribute."; }; }) - (mkIf cfg.enable { - networking.firewall.allowedTCPPorts = optional cfg.openFirewall cfg.port; + (lib.mkIf cfg.enable { + networking.firewall.allowedTCPPorts = lib.optional cfg.openFirewall cfg.port; systemd.services.alertmanager = { wantedBy = [ "multi-user.target" ]; @@ -188,8 +185,8 @@ in { ''; serviceConfig = { ExecStart = "${cfg.package}/bin/alertmanager" + - optionalString (length cmdlineArgs != 0) (" \\\n " + - concatStringsSep " \\\n " cmdlineArgs); + lib.optionalString (lib.length cmdlineArgs != 0) (" \\\n " + + lib.concatStringsSep " \\\n " cmdlineArgs); ExecReload = "${pkgs.coreutils}/bin/kill -HUP $MAINPID"; EnvironmentFile = lib.mkIf (cfg.environmentFile != null) cfg.environmentFile; From 3b6ddc5927f3c0d5f29ba82da23d7bd03e500a72 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:01 +0200 Subject: [PATCH 131/166] nixos/services.prometheus.pushgateway: remove `with lib;` --- .../monitoring/prometheus/pushgateway.nix | 59 +++++++++---------- 1 file changed, 28 insertions(+), 31 deletions(-) diff --git a/nixos/modules/services/monitoring/prometheus/pushgateway.nix b/nixos/modules/services/monitoring/prometheus/pushgateway.nix index d4f9c4a29f38..ebc8b9d889dc 100644 --- a/nixos/modules/services/monitoring/prometheus/pushgateway.nix +++ b/nixos/modules/services/monitoring/prometheus/pushgateway.nix @@ -1,7 +1,4 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.services.prometheus.pushgateway; @@ -10,23 +7,23 @@ let ++ opt "web.telemetry-path" cfg.web.telemetry-path ++ opt "web.external-url" cfg.web.external-url ++ opt "web.route-prefix" cfg.web.route-prefix - ++ optional cfg.persistMetrics ''--persistence.file="/var/lib/${cfg.stateDir}/metrics"'' + ++ lib.optional cfg.persistMetrics ''--persistence.file="/var/lib/${cfg.stateDir}/metrics"'' ++ opt "persistence.interval" cfg.persistence.interval ++ opt "log.level" cfg.log.level ++ opt "log.format" cfg.log.format ++ cfg.extraFlags; - opt = k : v : optional (v != null) ''--${k}="${v}"''; + opt = k : v : lib.optional (v != null) ''--${k}="${v}"''; in { options = { services.prometheus.pushgateway = { - enable = mkEnableOption "Prometheus Pushgateway"; + enable = lib.mkEnableOption "Prometheus Pushgateway"; - package = mkPackageOption pkgs "prometheus-pushgateway" { }; + package = lib.mkPackageOption pkgs "prometheus-pushgateway" { }; - web.listen-address = mkOption { - type = types.nullOr types.str; + web.listen-address = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; description = '' Address to listen on for the web interface, API and telemetry. @@ -35,8 +32,8 @@ in { ''; }; - web.telemetry-path = mkOption { - type = types.nullOr types.str; + web.telemetry-path = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; description = '' Path under which to expose metrics. @@ -45,16 +42,16 @@ in { ''; }; - web.external-url = mkOption { - type = types.nullOr types.str; + web.external-url = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; description = '' The URL under which Pushgateway is externally reachable. ''; }; - web.route-prefix = mkOption { - type = types.nullOr types.str; + web.route-prefix = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; description = '' Prefix for the internal routes of web endpoints. @@ -64,8 +61,8 @@ in { ''; }; - persistence.interval = mkOption { - type = types.nullOr types.str; + persistence.interval = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; example = "10m"; description = '' @@ -75,8 +72,8 @@ in { ''; }; - log.level = mkOption { - type = types.nullOr (types.enum ["debug" "info" "warn" "error" "fatal"]); + log.level = lib.mkOption { + type = lib.types.nullOr (lib.types.enum ["debug" "info" "warn" "error" "fatal"]); default = null; description = '' Only log messages with the given severity or above. @@ -85,8 +82,8 @@ in { ''; }; - log.format = mkOption { - type = types.nullOr types.str; + log.format = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; example = "logger:syslog?appname=bob&local=7"; description = '' @@ -96,16 +93,16 @@ in { ''; }; - extraFlags = mkOption { - type = types.listOf types.str; + extraFlags = lib.mkOption { + type = lib.types.listOf lib.types.str; default = []; description = '' Extra commandline options when launching the Pushgateway. ''; }; - persistMetrics = mkOption { - type = types.bool; + persistMetrics = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether to persist metrics to a file. @@ -118,8 +115,8 @@ in { ''; }; - stateDir = mkOption { - type = types.str; + stateDir = lib.mkOption { + type = lib.types.str; default = "pushgateway"; description = '' Directory below `/var/lib` to store metrics. @@ -133,10 +130,10 @@ in { }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { assertions = [ { - assertion = !hasPrefix "/" cfg.stateDir; + assertion = !lib.hasPrefix "/" cfg.stateDir; message = "The option services.prometheus.pushgateway.stateDir" + " shouldn't be an absolute directory." + @@ -148,8 +145,8 @@ in { after = [ "network.target" ]; serviceConfig = { ExecStart = "${cfg.package}/bin/pushgateway" + - optionalString (length cmdlineArgs != 0) (" \\\n " + - concatStringsSep " \\\n " cmdlineArgs); + lib.optionalString (lib.length cmdlineArgs != 0) (" \\\n " + + lib.concatStringsSep " \\\n " cmdlineArgs); CapabilityBoundingSet = [ "" ]; DeviceAllow = [ "" ]; From f9825ae1002781ebb60ea72944e512b55bb2d291 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:02 +0200 Subject: [PATCH 132/166] nixos/services.prometheus.sachet: remove `with lib;` --- .../services/monitoring/prometheus/sachet.nix | 23 ++++++++----------- 1 file changed, 10 insertions(+), 13 deletions(-) diff --git a/nixos/modules/services/monitoring/prometheus/sachet.nix b/nixos/modules/services/monitoring/prometheus/sachet.nix index 3deb29aeb222..bc1416308f16 100644 --- a/nixos/modules/services/monitoring/prometheus/sachet.nix +++ b/nixos/modules/services/monitoring/prometheus/sachet.nix @@ -1,7 +1,4 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.services.prometheus.sachet; configFile = pkgs.writeText "sachet.yml" (builtins.toJSON cfg.configuration); @@ -9,12 +6,12 @@ in { options = { services.prometheus.sachet = { - enable = mkEnableOption "Sachet, an SMS alerting tool for the Prometheus Alertmanager"; + enable = lib.mkEnableOption "Sachet, an SMS alerting tool for the Prometheus Alertmanager"; - configuration = mkOption { - type = types.nullOr types.attrs; + configuration = lib.mkOption { + type = lib.types.nullOr lib.types.attrs; default = null; - example = literalExpression '' + example = lib.literalExpression '' { providers = { twilio = { @@ -37,16 +34,16 @@ in ''; }; - address = mkOption { - type = types.str; + address = lib.mkOption { + type = lib.types.str; default = "localhost"; description = '' The address Sachet will listen to. ''; }; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 9876; description = '' The port Sachet will listen to. @@ -56,8 +53,8 @@ in }; }; - config = mkIf cfg.enable { - assertions = singleton { + config = lib.mkIf cfg.enable { + assertions = lib.singleton { assertion = cfg.configuration != null; message = "Cannot enable Sachet without a configuration."; }; From 4f4731400344d93b5fd830b7df0548a7a8b12b55 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:02 +0200 Subject: [PATCH 133/166] nixos/services.prometheus.xmpp-alerts: remove `with lib;` --- .../services/monitoring/prometheus/xmpp-alerts.nix | 11 ++++------- 1 file changed, 4 insertions(+), 7 deletions(-) diff --git a/nixos/modules/services/monitoring/prometheus/xmpp-alerts.nix b/nixos/modules/services/monitoring/prometheus/xmpp-alerts.nix index f3f553cd8642..2e367e47cc61 100644 --- a/nixos/modules/services/monitoring/prometheus/xmpp-alerts.nix +++ b/nixos/modules/services/monitoring/prometheus/xmpp-alerts.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.prometheus.xmpp-alerts; settingsFormat = pkgs.formats.yaml {}; @@ -9,15 +6,15 @@ let in { imports = [ - (mkRenamedOptionModule + (lib.mkRenamedOptionModule [ "services" "prometheus" "xmpp-alerts" "configuration" ] [ "services" "prometheus" "xmpp-alerts" "settings" ]) ]; options.services.prometheus.xmpp-alerts = { - enable = mkEnableOption "XMPP Web hook service for Alertmanager"; + enable = lib.mkEnableOption "XMPP Web hook service for Alertmanager"; - settings = mkOption { + settings = lib.mkOption { type = settingsFormat.type; default = {}; @@ -29,7 +26,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.prometheus-xmpp-alerts = { wantedBy = [ "multi-user.target" ]; after = [ "network-online.target" ]; From 9f025e3df5437e5a1492399e6b783375d8195ee7 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:03 +0200 Subject: [PATCH 134/166] nixos/services.riemann-dash: remove `with lib;` --- .../services/monitoring/riemann-dash.nix | 22 ++++++++----------- 1 file changed, 9 insertions(+), 13 deletions(-) diff --git a/nixos/modules/services/monitoring/riemann-dash.nix b/nixos/modules/services/monitoring/riemann-dash.nix index 243d0edb3aae..47db86035e40 100644 --- a/nixos/modules/services/monitoring/riemann-dash.nix +++ b/nixos/modules/services/monitoring/riemann-dash.nix @@ -1,19 +1,15 @@ { config, pkgs, lib, ... }: - -with pkgs; -with lib; - let cfg = config.services.riemann-dash; - conf = writeText "config.rb" '' + conf = pkgs.writeText "config.rb" '' riemann_base = "${cfg.dataDir}" config.store[:ws_config] = "#{riemann_base}/config/config.json" ${cfg.config} ''; - launcher = writeScriptBin "riemann-dash" '' + launcher = pkgs.writeScriptBin "riemann-dash" '' #!/bin/sh exec ${pkgs.riemann-dash}/bin/riemann-dash ${conf} ''; @@ -23,21 +19,21 @@ in { options = { services.riemann-dash = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = '' Enable the riemann-dash dashboard daemon. ''; }; - config = mkOption { - type = types.lines; + config = lib.mkOption { + type = lib.types.lines; description = '' Contents added to the end of the riemann-dash configuration file. ''; }; - dataDir = mkOption { - type = types.str; + dataDir = lib.mkOption { + type = lib.types.str; default = "/var/riemann-dash"; description = '' Location of the riemann-base dir. The dashboard configuration file is @@ -49,7 +45,7 @@ in { }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { users.groups.riemanndash.gid = config.ids.gids.riemanndash; From 36b176c8e31f0baadf57d47e9f7bff2b91189374 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:03 +0200 Subject: [PATCH 135/166] nixos/services.riemann-tools: remove `with lib;` --- .../services/monitoring/riemann-tools.nix | 22 ++++++++----------- 1 file changed, 9 insertions(+), 13 deletions(-) diff --git a/nixos/modules/services/monitoring/riemann-tools.nix b/nixos/modules/services/monitoring/riemann-tools.nix index 86a11694e7b4..fc15dcf85344 100644 --- a/nixos/modules/services/monitoring/riemann-tools.nix +++ b/nixos/modules/services/monitoring/riemann-tools.nix @@ -1,15 +1,11 @@ { config, pkgs, lib, ... }: - -with pkgs; -with lib; - let cfg = config.services.riemann-tools; riemannHost = "${cfg.riemannHost}"; - healthLauncher = writeScriptBin "riemann-health" '' + healthLauncher = pkgs.writeScriptBin "riemann-health" '' #!/bin/sh exec ${pkgs.riemann-tools}/bin/riemann-health ${builtins.concatStringsSep " " cfg.extraArgs} --host ${riemannHost} ''; @@ -20,22 +16,22 @@ in { options = { services.riemann-tools = { - enableHealth = mkOption { - type = types.bool; + enableHealth = lib.mkOption { + type = lib.types.bool; default = false; description = '' Enable the riemann-health daemon. ''; }; - riemannHost = mkOption { - type = types.str; + riemannHost = lib.mkOption { + type = lib.types.str; default = "127.0.0.1"; description = '' Address of the host riemann node. Defaults to localhost. ''; }; - extraArgs = mkOption { - type = types.listOf types.str; + extraArgs = lib.mkOption { + type = lib.types.listOf lib.types.str; default = []; description = '' A list of commandline-switches forwarded to a riemann-tool. @@ -46,7 +42,7 @@ in { }; }; - config = mkIf cfg.enableHealth { + config = lib.mkIf cfg.enableHealth { users.groups.riemanntools.gid = config.ids.gids.riemanntools; @@ -58,7 +54,7 @@ in { systemd.services.riemann-health = { wantedBy = [ "multi-user.target" ]; - path = [ procps ]; + path = [ pkgs.procps ]; serviceConfig = { User = "riemanntools"; ExecStart = "${healthLauncher}/bin/riemann-health"; From a7f917375fca68011b39463123c93c9578add67f Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:03 +0200 Subject: [PATCH 136/166] nixos/services.riemann: remove `with lib;` --- nixos/modules/services/monitoring/riemann.nix | 44 +++++++++---------- 1 file changed, 20 insertions(+), 24 deletions(-) diff --git a/nixos/modules/services/monitoring/riemann.nix b/nixos/modules/services/monitoring/riemann.nix index fd625e34e013..97ae9e2211af 100644 --- a/nixos/modules/services/monitoring/riemann.nix +++ b/nixos/modules/services/monitoring/riemann.nix @@ -1,23 +1,19 @@ { config, pkgs, lib, ... }: - -with pkgs; -with lib; - let cfg = config.services.riemann; - classpath = concatStringsSep ":" ( - cfg.extraClasspathEntries ++ [ "${riemann}/share/java/riemann.jar" ] + classpath = lib.concatStringsSep ":" ( + cfg.extraClasspathEntries ++ [ "${pkgs.riemann}/share/java/riemann.jar" ] ); - riemannConfig = concatStringsSep "\n" ( + riemannConfig = lib.concatStringsSep "\n" ( [cfg.config] ++ (map (f: ''(load-file "${f}")'') cfg.configFiles) ); - launcher = writeScriptBin "riemann" '' + launcher = pkgs.writeScriptBin "riemann" '' #!/bin/sh - exec ${jdk}/bin/java ${concatStringsSep " " cfg.extraJavaOpts} \ + exec ${pkgs.jdk}/bin/java ${lib.concatStringsSep " " cfg.extraJavaOpts} \ -cp ${classpath} \ riemann.bin ${cfg.configFile} ''; @@ -27,17 +23,17 @@ in { options = { services.riemann = { - enable = mkEnableOption "Riemann network monitoring daemon"; + enable = lib.mkEnableOption "Riemann network monitoring daemon"; - config = mkOption { - type = types.lines; + config = lib.mkOption { + type = lib.types.lines; description = '' Contents of the Riemann configuration file. For more complicated config you should use configFile. ''; }; - configFiles = mkOption { - type = with types; listOf path; + configFiles = lib.mkOption { + type = with lib.types; listOf path; default = []; description = '' Extra files containing Riemann configuration. These files will be @@ -47,22 +43,22 @@ in { use configFile. ''; }; - configFile = mkOption { - type = types.str; + configFile = lib.mkOption { + type = lib.types.str; description = '' A Riemann config file. Any files in the same directory as this file will be added to the classpath by Riemann. ''; }; - extraClasspathEntries = mkOption { - type = with types; listOf str; + extraClasspathEntries = lib.mkOption { + type = with lib.types; listOf str; default = []; description = '' Extra entries added to the Java classpath when running Riemann. ''; }; - extraJavaOpts = mkOption { - type = with types; listOf str; + extraJavaOpts = lib.mkOption { + type = with lib.types; listOf str; default = []; description = '' Extra Java options used when launching Riemann. @@ -71,7 +67,7 @@ in { }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { users.groups.riemann.gid = config.ids.gids.riemann; @@ -81,13 +77,13 @@ in { group = "riemann"; }; - services.riemann.configFile = mkDefault ( - writeText "riemann-config.clj" riemannConfig + services.riemann.configFile = lib.mkDefault ( + pkgs.writeText "riemann-config.clj" riemannConfig ); systemd.services.riemann = { wantedBy = [ "multi-user.target" ]; - path = [ inetutils ]; + path = [ pkgs.inetutils ]; serviceConfig = { User = "riemann"; ExecStart = "${launcher}/bin/riemann"; From b3796eddc4288e8e25009f389080216bb7f87dea Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:03 +0200 Subject: [PATCH 137/166] nixos/services.scollector: remove `with lib;` --- .../services/monitoring/scollector.nix | 37 +++++++++---------- 1 file changed, 17 insertions(+), 20 deletions(-) diff --git a/nixos/modules/services/monitoring/scollector.nix b/nixos/modules/services/monitoring/scollector.nix index 49c3788e086f..19625e057436 100644 --- a/nixos/modules/services/monitoring/scollector.nix +++ b/nixos/modules/services/monitoring/scollector.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.scollector; @@ -32,34 +29,34 @@ in { services.scollector = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether to run scollector. ''; }; - package = mkPackageOption pkgs "scollector" { }; + package = lib.mkPackageOption pkgs "scollector" { }; - user = mkOption { - type = types.str; + user = lib.mkOption { + type = lib.types.str; default = "scollector"; description = '' User account under which scollector runs. ''; }; - group = mkOption { - type = types.str; + group = lib.mkOption { + type = lib.types.str; default = "scollector"; description = '' Group account under which scollector runs. ''; }; - bosunHost = mkOption { - type = types.str; + bosunHost = lib.mkOption { + type = lib.types.str; default = "localhost:8070"; description = '' Host and port of the bosun server that will store the collected @@ -67,10 +64,10 @@ in { ''; }; - collectors = mkOption { - type = with types; attrsOf (listOf path); + collectors = lib.mkOption { + type = with lib.types; attrsOf (listOf path); default = {}; - example = literalExpression ''{ "0" = [ "''${postgresStats}/bin/collect-stats" ]; }''; + example = lib.literalExpression ''{ "0" = [ "''${postgresStats}/bin/collect-stats" ]; }''; description = '' An attribute set mapping the frequency of collection to a list of binaries that should be executed at that frequency. You can use "0" @@ -78,8 +75,8 @@ in { ''; }; - extraOpts = mkOption { - type = with types; listOf str; + extraOpts = lib.mkOption { + type = with lib.types; listOf str; default = []; example = [ "-d" ]; description = '' @@ -87,8 +84,8 @@ in { ''; }; - extraConfig = mkOption { - type = types.lines; + extraConfig = lib.mkOption { + type = lib.types.lines; default = ""; description = '' Extra scollector configuration added to the end of scollector.toml @@ -99,7 +96,7 @@ in { }; - config = mkIf config.services.scollector.enable { + config = lib.mkIf config.services.scollector.enable { systemd.services.scollector = { description = "scollector metrics collector (part of Bosun)"; From 084011a1b4f6fc6e04fdd52e3c38381009e70465 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:04 +0200 Subject: [PATCH 138/166] nixos/services.smartd: remove `with lib;` --- nixos/modules/services/monitoring/smartd.nix | 97 ++++++++++---------- 1 file changed, 47 insertions(+), 50 deletions(-) diff --git a/nixos/modules/services/monitoring/smartd.nix b/nixos/modules/services/monitoring/smartd.nix index 65b6259c12bd..2cb5897f5d4c 100644 --- a/nixos/modules/services/monitoring/smartd.nix +++ b/nixos/modules/services/monitoring/smartd.nix @@ -1,7 +1,4 @@ { config, lib, options, pkgs, ... }: - -with lib; - let host = config.networking.fqdnOrHostName; @@ -16,7 +13,7 @@ let smartdNotify = pkgs.writeScript "smartd-notify.sh" '' #! ${pkgs.runtimeShell} - ${optionalString nm.enable '' + ${lib.optionalString nm.enable '' { ${pkgs.coreutils}/bin/cat << EOF From: smartd on ${host} <${nm.sender}> @@ -29,13 +26,13 @@ let ${pkgs.smartmontools}/sbin/smartctl -a -d "$SMARTD_DEVICETYPE" "$SMARTD_DEVICE" } | ${nm.mailer} -i "${nm.recipient}" ''} - ${optionalString ns.enable '' + ${lib.optionalString ns.enable '' ${pkgs.dbus}/bin/dbus-send --system \ / net.nuetzlich.SystemNotifications.Notify \ "string:Problem detected with disk: $SMARTD_DEVICESTRING" \ "string:Warning message from smartd is: $SMARTD_MESSAGE" ''} - ${optionalString nw.enable '' + ${lib.optionalString nw.enable '' { ${pkgs.coreutils}/bin/cat << EOF Problem detected with disk: $SMARTD_DEVICESTRING @@ -45,7 +42,7 @@ let EOF } | ${pkgs.util-linux}/bin/wall 2>/dev/null ''} - ${optionalString nx.enable '' + ${lib.optionalString nx.enable '' export DISPLAY=${nx.display} { ${pkgs.coreutils}/bin/cat << EOF @@ -58,16 +55,16 @@ let ''} ''; - notifyOpts = optionalString (nm.enable || nw.enable || nx.enable) - ("-m -M exec ${smartdNotify} " + optionalString cfg.notifications.test "-M test "); + notifyOpts = lib.optionalString (nm.enable || nw.enable || nx.enable) + ("-m -M exec ${smartdNotify} " + lib.optionalString cfg.notifications.test "-M test "); smartdConf = pkgs.writeText "smartd.conf" '' # Autogenerated smartd startup config file DEFAULT ${notifyOpts}${cfg.defaults.monitored} - ${concatMapStringsSep "\n" (d: "${d.device} ${d.options}") cfg.devices} + ${lib.concatMapStringsSep "\n" (d: "${d.device} ${d.options}") cfg.devices} - ${optionalString cfg.autodetect + ${lib.optionalString cfg.autodetect "DEVICESCAN ${notifyOpts}${cfg.defaults.autodetected}"} ''; @@ -75,16 +72,16 @@ let options = { - device = mkOption { + device = lib.mkOption { example = "/dev/sda"; - type = types.str; + type = lib.types.str; description = "Location of the device."; }; - options = mkOption { + options = lib.mkOption { default = ""; example = "-d sat"; - type = types.separatedString " "; + type = lib.types.separatedString " "; description = "Options that determine how smartd monitors the device."; }; @@ -101,11 +98,11 @@ in services.smartd = { - enable = mkEnableOption "smartd daemon from `smartmontools` package"; + enable = lib.mkEnableOption "smartd daemon from `smartmontools` package"; - autodetect = mkOption { + autodetect = lib.mkOption { default = true; - type = types.bool; + type = lib.types.bool; description = '' Whenever smartd should monitor all devices connected to the machine at the time it's being started (the default). @@ -115,9 +112,9 @@ in ''; }; - extraOptions = mkOption { + extraOptions = lib.mkOption { default = []; - type = types.listOf types.str; + type = lib.types.listOf lib.types.str; example = ["-A /var/log/smartd/" "--interval=3600"]; description = '' Extra command-line options passed to the `smartd` @@ -130,32 +127,32 @@ in notifications = { mail = { - enable = mkOption { + enable = lib.mkOption { default = config.services.mail.sendmailSetuidWrapper != null; - defaultText = literalExpression "config.services.mail.sendmailSetuidWrapper != null"; - type = types.bool; + defaultText = lib.literalExpression "config.services.mail.sendmailSetuidWrapper != null"; + type = lib.types.bool; description = "Whenever to send e-mail notifications."; }; - sender = mkOption { + sender = lib.mkOption { default = "root"; example = "example@domain.tld"; - type = types.str; + type = lib.types.str; description = '' Sender of the notification messages. Acts as the value of `email` in the emails' `From: ...` field. ''; }; - recipient = mkOption { + recipient = lib.mkOption { default = "root"; - type = types.str; + type = lib.types.str; description = "Recipient of the notification messages."; }; - mailer = mkOption { + mailer = lib.mkOption { default = "/run/wrappers/bin/sendmail"; - type = types.path; + type = lib.types.path; description = '' Sendmail-compatible binary to be used to send the messages. @@ -167,9 +164,9 @@ in }; systembus-notify = { - enable = mkOption { + enable = lib.mkOption { default = false; - type = types.bool; + type = lib.types.bool; description = '' Whenever to send systembus-notify notifications. @@ -185,41 +182,41 @@ in }; wall = { - enable = mkOption { + enable = lib.mkOption { default = true; - type = types.bool; + type = lib.types.bool; description = "Whenever to send wall notifications to all users."; }; }; x11 = { - enable = mkOption { + enable = lib.mkOption { default = config.services.xserver.enable; - defaultText = literalExpression "config.services.xserver.enable"; - type = types.bool; + defaultText = lib.literalExpression "config.services.xserver.enable"; + type = lib.types.bool; description = "Whenever to send X11 xmessage notifications."; }; - display = mkOption { + display = lib.mkOption { default = ":${toString config.services.xserver.display}"; - defaultText = literalExpression ''":''${toString config.services.xserver.display}"''; - type = types.str; + defaultText = lib.literalExpression ''":''${toString config.services.xserver.display}"''; + type = lib.types.str; description = "DISPLAY to send X11 notifications to."; }; }; - test = mkOption { + test = lib.mkOption { default = false; - type = types.bool; + type = lib.types.bool; description = "Whenever to send a test notification on startup."; }; }; defaults = { - monitored = mkOption { + monitored = lib.mkOption { default = "-a"; - type = types.separatedString " "; + type = lib.types.separatedString " "; example = "-a -o on -s (S/../.././02|L/../../7/04)"; description = '' Common default options for explicitly monitored (listed in @@ -234,10 +231,10 @@ in ''; }; - autodetected = mkOption { + autodetected = lib.mkOption { default = cfg.defaults.monitored; - defaultText = literalExpression "config.${opt.defaults.monitored}"; - type = types.separatedString " "; + defaultText = lib.literalExpression "config.${opt.defaults.monitored}"; + type = lib.types.separatedString " "; description = '' Like {option}`services.smartd.defaults.monitored`, but for the autodetected devices. @@ -245,10 +242,10 @@ in }; }; - devices = mkOption { + devices = lib.mkOption { default = []; example = [ { device = "/dev/sda"; } { device = "/dev/sdb"; options = "-d sat"; } ]; - type = with types; listOf (submodule smartdDeviceOpts); + type = with lib.types; listOf (submodule smartdDeviceOpts); description = "List of devices to monitor."; }; @@ -259,7 +256,7 @@ in ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { assertions = [ { assertion = cfg.autodetect || cfg.devices != []; @@ -275,7 +272,7 @@ in }; }; - services.systembus-notify.enable = mkDefault ns.enable; + services.systembus-notify.enable = lib.mkDefault ns.enable; }; From 8b8b523eb932dec9cc4503fab897e87c5e759baa Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:04 +0200 Subject: [PATCH 139/166] nixos/services.statsd: remove `with lib;` --- nixos/modules/services/monitoring/statsd.nix | 51 +++++++++----------- 1 file changed, 24 insertions(+), 27 deletions(-) diff --git a/nixos/modules/services/monitoring/statsd.nix b/nixos/modules/services/monitoring/statsd.nix index 30b2916a9928..814d00fadc3b 100644 --- a/nixos/modules/services/monitoring/statsd.nix +++ b/nixos/modules/services/monitoring/statsd.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.statsd; @@ -13,7 +10,7 @@ let mkMap = list: name: if isBuiltinBackend name then list else list ++ [ pkgs.nodePackages.${name} ]; - in foldl mkMap []; + in lib.foldl mkMap []; configFile = pkgs.writeText "statsd.conf" '' { @@ -22,20 +19,20 @@ let mgmt_address: "${cfg.mgmt_address}", mgmt_port: "${toString cfg.mgmt_port}", backends: [${ - concatMapStringsSep "," (name: + lib.concatMapStringsSep "," (name: if (isBuiltinBackend name) then ''"./backends/${name}"'' else ''"${name}"'' ) cfg.backends}], - ${optionalString (cfg.graphiteHost!=null) ''graphiteHost: "${cfg.graphiteHost}",''} - ${optionalString (cfg.graphitePort!=null) ''graphitePort: "${toString cfg.graphitePort}",''} + ${lib.optionalString (cfg.graphiteHost!=null) ''graphiteHost: "${cfg.graphiteHost}",''} + ${lib.optionalString (cfg.graphitePort!=null) ''graphitePort: "${toString cfg.graphitePort}",''} console: { prettyprint: false }, log: { backend: "stdout" }, - automaticConfigReload: false${optionalString (cfg.extraConfig != null) ","} + automaticConfigReload: false${lib.optionalString (cfg.extraConfig != null) ","} ${cfg.extraConfig} } ''; @@ -56,33 +53,33 @@ in options.services.statsd = { - enable = mkEnableOption "statsd"; + enable = lib.mkEnableOption "statsd"; - listenAddress = mkOption { + listenAddress = lib.mkOption { description = "Address that statsd listens on over UDP"; default = "127.0.0.1"; - type = types.str; + type = lib.types.str; }; - port = mkOption { + port = lib.mkOption { description = "Port that stats listens for messages on over UDP"; default = 8125; - type = types.int; + type = lib.types.int; }; - mgmt_address = mkOption { + mgmt_address = lib.mkOption { description = "Address to run management TCP interface on"; default = "127.0.0.1"; - type = types.str; + type = lib.types.str; }; - mgmt_port = mkOption { + mgmt_port = lib.mkOption { description = "Port to run the management TCP interface on"; default = 8126; - type = types.int; + type = lib.types.int; }; - backends = mkOption { + backends = lib.mkOption { description = "List of backends statsd will use for data persistence"; default = []; example = [ @@ -93,35 +90,35 @@ in "stackdriver-statsd-backend" "statsd-influxdb-backend" ]; - type = types.listOf types.str; + type = lib.types.listOf lib.types.str; }; - graphiteHost = mkOption { + graphiteHost = lib.mkOption { description = "Hostname or IP of Graphite server"; default = null; - type = types.nullOr types.str; + type = lib.types.nullOr lib.types.str; }; - graphitePort = mkOption { + graphitePort = lib.mkOption { description = "Port of Graphite server (i.e. carbon-cache)."; default = null; - type = types.nullOr types.int; + type = lib.types.nullOr lib.types.int; }; - extraConfig = mkOption { + extraConfig = lib.mkOption { description = "Extra configuration options for statsd"; default = ""; - type = types.nullOr types.str; + type = lib.types.nullOr lib.types.str; }; }; ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { assertions = map (backend: { - assertion = !isBuiltinBackend backend -> hasAttrByPath [ backend ] pkgs.nodePackages; + assertion = !isBuiltinBackend backend -> lib.hasAttrByPath [ backend ] pkgs.nodePackages; message = "Only builtin backends (graphite, console, repeater) or backends enumerated in `pkgs.nodePackages` are allowed!"; }) cfg.backends; From 8eb355e9780719b21a39862d64fbb081c7f74d29 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:04 +0200 Subject: [PATCH 140/166] nixos/services.sysstat: remove `with lib;` --- nixos/modules/services/monitoring/sysstat.nix | 13 ++++++------- 1 file changed, 6 insertions(+), 7 deletions(-) diff --git a/nixos/modules/services/monitoring/sysstat.nix b/nixos/modules/services/monitoring/sysstat.nix index ca2cff827232..ca674defd65e 100644 --- a/nixos/modules/services/monitoring/sysstat.nix +++ b/nixos/modules/services/monitoring/sysstat.nix @@ -1,22 +1,21 @@ { config, lib, pkgs, ... }: -with lib; let cfg = config.services.sysstat; in { options = { services.sysstat = { - enable = mkEnableOption "sar system activity collection"; + enable = lib.mkEnableOption "sar system activity collection"; - collect-frequency = mkOption { - type = types.str; + collect-frequency = lib.mkOption { + type = lib.types.str; default = "*:00/10"; description = '' OnCalendar specification for sysstat-collect ''; }; - collect-args = mkOption { - type = types.str; + collect-args = lib.mkOption { + type = lib.types.str; default = "1 1"; description = '' Arguments to pass sa1 when collecting statistics @@ -25,7 +24,7 @@ in { }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.sysstat = { description = "Resets System Activity Logs"; wantedBy = [ "multi-user.target" ]; From 851d23320b41f39df64b86390b1e65493b9d0025 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:05 +0200 Subject: [PATCH 141/166] nixos/services.telegraf: remove `with lib;` --- nixos/modules/services/monitoring/telegraf.nix | 15 ++++++--------- 1 file changed, 6 insertions(+), 9 deletions(-) diff --git a/nixos/modules/services/monitoring/telegraf.nix b/nixos/modules/services/monitoring/telegraf.nix index dfff80e1bac2..06339269b427 100644 --- a/nixos/modules/services/monitoring/telegraf.nix +++ b/nixos/modules/services/monitoring/telegraf.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.telegraf; @@ -11,12 +8,12 @@ in { ###### interface options = { services.telegraf = { - enable = mkEnableOption "telegraf server"; + enable = lib.mkEnableOption "telegraf server"; - package = mkPackageOption pkgs "telegraf" { }; + package = lib.mkPackageOption pkgs "telegraf" { }; - environmentFiles = mkOption { - type = types.listOf types.path; + environmentFiles = lib.mkOption { + type = lib.types.listOf lib.types.path; default = []; example = [ "/run/keys/telegraf.env" ]; description = '' @@ -27,7 +24,7 @@ in { ''; }; - extraConfig = mkOption { + extraConfig = lib.mkOption { default = {}; description = "Extra configuration options for telegraf"; type = settingsFormat.type; @@ -47,7 +44,7 @@ in { ###### implementation - config = mkIf config.services.telegraf.enable { + config = lib.mkIf config.services.telegraf.enable { services.telegraf.extraConfig = { inputs = {}; outputs = {}; From 307f280e81ebca7f32a87e1c463b9dc7c55eeda4 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:05 +0200 Subject: [PATCH 142/166] nixos/services.tremor-rs: remove `with lib;` --- .../modules/services/monitoring/tremor-rs.nix | 26 +++++++++---------- 1 file changed, 12 insertions(+), 14 deletions(-) diff --git a/nixos/modules/services/monitoring/tremor-rs.nix b/nixos/modules/services/monitoring/tremor-rs.nix index c8a77ab93def..ebd27771c239 100644 --- a/nixos/modules/services/monitoring/tremor-rs.nix +++ b/nixos/modules/services/monitoring/tremor-rs.nix @@ -1,6 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; let cfg = config.services.tremor-rs; @@ -13,31 +11,31 @@ in { services.tremor-rs = { enable = lib.mkEnableOption "Tremor event- or stream-processing system"; - troyFileList = mkOption { - type = types.listOf types.path; + troyFileList = lib.mkOption { + type = lib.types.listOf lib.types.path; default = []; description = "List of troy files to load."; }; - tremorLibDir = mkOption { - type = types.path; + tremorLibDir = lib.mkOption { + type = lib.types.path; default = ""; description = "Directory where to find /lib containing tremor script files"; }; - host = mkOption { - type = types.str; + host = lib.mkOption { + type = lib.types.str; default = "127.0.0.1"; description = "The host tremor should be listening on"; }; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 9898; description = "the port tremor should be listening on"; }; - loggerSettings = mkOption { + loggerSettings = lib.mkOption { description = "Tremor logger configuration"; default = {}; type = loggerSettingsFormat.type; @@ -63,7 +61,7 @@ in { }; }; - defaultText = literalExpression '' + defaultText = lib.literalExpression '' { refresh_rate = "30 seconds"; appenders.stdout.kind = "console"; @@ -90,7 +88,7 @@ in { }; }; - config = mkIf (cfg.enable) { + config = lib.mkIf (cfg.enable) { environment.systemPackages = [ pkgs.tremor-rs ] ; @@ -103,7 +101,7 @@ in { environment.TREMOR_PATH = "${pkgs.tremor-rs}/lib:${cfg.tremorLibDir}"; serviceConfig = { - ExecStart = "${pkgs.tremor-rs}/bin/tremor --logger-config ${loggerConfigFile} server run ${concatStringsSep " " cfg.troyFileList} --api-host ${cfg.host}:${toString cfg.port}"; + ExecStart = "${pkgs.tremor-rs}/bin/tremor --logger-config ${loggerConfigFile} server run ${lib.concatStringsSep " " cfg.troyFileList} --api-host ${cfg.host}:${toString cfg.port}"; DynamicUser = true; Restart = "always"; NoNewPrivileges = true; From 6974870a0a5d7dbc7cdd8ed86362cedbc76ee8b7 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:06 +0200 Subject: [PATCH 143/166] nixos/services.tuptime: remove `with lib;` --- nixos/modules/services/monitoring/tuptime.nix | 21 ++++++++----------- 1 file changed, 9 insertions(+), 12 deletions(-) diff --git a/nixos/modules/services/monitoring/tuptime.nix b/nixos/modules/services/monitoring/tuptime.nix index 334f911a6c71..07ada853760b 100644 --- a/nixos/modules/services/monitoring/tuptime.nix +++ b/nixos/modules/services/monitoring/tuptime.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.tuptime; @@ -10,17 +7,17 @@ in { options.services.tuptime = { - enable = mkEnableOption "the total uptime service"; + enable = lib.mkEnableOption "the total uptime service"; timer = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = true; description = "Whether to regularly log uptime to detect bad shutdowns."; }; - period = mkOption { - type = types.str; + period = lib.mkOption { + type = lib.types.str; default = "*:0/5"; description = "systemd calendar event"; }; @@ -28,7 +25,7 @@ in { }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = [ pkgs.tuptime ]; @@ -59,7 +56,7 @@ in { }; }; - tuptime-sync = mkIf cfg.timer.enable { + tuptime-sync = lib.mkIf cfg.timer.enable { description = "Tuptime scheduled sync service"; serviceConfig = { Type = "oneshot"; @@ -69,7 +66,7 @@ in { }; }; - timers.tuptime-sync = mkIf cfg.timer.enable { + timers.tuptime-sync = lib.mkIf cfg.timer.enable { description = "Tuptime scheduled sync timer"; # this timer should be started if the service is started # even if the timer was previously stopped @@ -85,6 +82,6 @@ in { }; }; - meta.maintainers = [ maintainers.evils ]; + meta.maintainers = [ lib.maintainers.evils ]; } From cc88c367bbe0982d7f3f754b90c7a952658b52b2 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:06 +0200 Subject: [PATCH 144/166] nixos/services.uptime-kuma: remove `with lib;` --- .../modules/services/monitoring/uptime-kuma.nix | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-) diff --git a/nixos/modules/services/monitoring/uptime-kuma.nix b/nixos/modules/services/monitoring/uptime-kuma.nix index 4c7dd900f52b..1d7ff10227a9 100644 --- a/nixos/modules/services/monitoring/uptime-kuma.nix +++ b/nixos/modules/services/monitoring/uptime-kuma.nix @@ -1,7 +1,4 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.services.uptime-kuma; in @@ -11,11 +8,11 @@ in options = { services.uptime-kuma = { - enable = mkEnableOption "Uptime Kuma, this assumes a reverse proxy to be set"; + enable = lib.mkEnableOption "Uptime Kuma, this assumes a reverse proxy to be set"; - package = mkPackageOption pkgs "uptime-kuma" { }; + package = lib.mkPackageOption pkgs "uptime-kuma" { }; - appriseSupport = mkEnableOption "apprise support for notifications"; + appriseSupport = lib.mkEnableOption "apprise support for notifications"; settings = lib.mkOption { type = lib.types.submodule { freeformType = with lib.types; attrsOf str; }; @@ -33,13 +30,13 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { services.uptime-kuma.settings = { DATA_DIR = "/var/lib/uptime-kuma/"; - NODE_ENV = mkDefault "production"; - HOST = mkDefault "127.0.0.1"; - PORT = mkDefault "3001"; + NODE_ENV = lib.mkDefault "production"; + HOST = lib.mkDefault "127.0.0.1"; + PORT = lib.mkDefault "3001"; }; systemd.services.uptime-kuma = { From e8e5c6c79b1385c6547095f8ca1940fcdc3b16b2 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:07 +0200 Subject: [PATCH 145/166] nixos/services.vnstat: remove `with lib;` --- nixos/modules/services/monitoring/vnstat.nix | 9 +++------ 1 file changed, 3 insertions(+), 6 deletions(-) diff --git a/nixos/modules/services/monitoring/vnstat.nix b/nixos/modules/services/monitoring/vnstat.nix index 5e19c399568d..afacb696420b 100644 --- a/nixos/modules/services/monitoring/vnstat.nix +++ b/nixos/modules/services/monitoring/vnstat.nix @@ -1,15 +1,12 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.vnstat; in { options.services.vnstat = { - enable = mkEnableOption "update of network usage statistics via vnstatd"; + enable = lib.mkEnableOption "update of network usage statistics via vnstatd"; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = [ pkgs.vnstat ]; @@ -56,5 +53,5 @@ in { }; }; - meta.maintainers = [ maintainers.evils ]; + meta.maintainers = [ lib.maintainers.evils ]; } From 5f44beaebbc8cccb59b79bdb713fcaff1be5287f Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:07 +0200 Subject: [PATCH 146/166] nixos/services.watchdogd: remove `with lib;` --- .../modules/services/monitoring/watchdogd.nix | 55 +++++++++---------- 1 file changed, 27 insertions(+), 28 deletions(-) diff --git a/nixos/modules/services/monitoring/watchdogd.nix b/nixos/modules/services/monitoring/watchdogd.nix index e8d104651c6a..f54d7aa80b18 100644 --- a/nixos/modules/services/monitoring/watchdogd.nix +++ b/nixos/modules/services/monitoring/watchdogd.nix @@ -1,33 +1,32 @@ { config, lib, pkgs, ... }: -with lib; let cfg = config.services.watchdogd; mkPluginOpts = plugin: defWarn: defCrit: { - enabled = mkEnableOption "watchdogd plugin ${plugin}"; - interval = mkOption { - type = types.ints.unsigned; + enabled = lib.mkEnableOption "watchdogd plugin ${plugin}"; + interval = lib.mkOption { + type = lib.types.ints.unsigned; default = 300; description = '' Amount of seconds between every poll. ''; }; - logmark = mkOption { - type = types.bool; + logmark = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether to log current stats every poll interval. ''; }; - warning = mkOption { - type = types.numbers.nonnegative; + warning = lib.mkOption { + type = lib.types.numbers.nonnegative; default = defWarn; description = '' The high watermark level. Alert sent to log. ''; }; - critical = mkOption { - type = types.numbers.nonnegative; + critical = lib.mkOption { + type = lib.types.numbers.nonnegative; default = defCrit; description = '' The critical watermark level. Alert sent to log, followed by reboot or script action. @@ -36,11 +35,11 @@ let }; in { options.services.watchdogd = { - enable = mkEnableOption "watchdogd, an advanced system & process supervisor"; - package = mkPackageOption pkgs "watchdogd" { }; + enable = lib.mkEnableOption "watchdogd, an advanced system & process supervisor"; + package = lib.mkPackageOption pkgs "watchdogd" { }; - settings = mkOption { - type = with types; submodule { + settings = lib.mkOption { + type = with lib.types; submodule { freeformType = let valueType = oneOf [ bool @@ -51,14 +50,14 @@ in { in attrsOf (either valueType (attrsOf valueType)); options = { - timeout = mkOption { + timeout = lib.mkOption { type = types.ints.unsigned; default = 15; description = '' The WDT timeout before reset. ''; }; - interval = mkOption { + interval = lib.mkOption { type = types.ints.unsigned; default = 5; description = '' @@ -66,7 +65,7 @@ in { ''; }; - safe-exit = mkOption { + safe-exit = lib.mkOption { type = types.bool; default = true; description = '' @@ -91,26 +90,26 @@ in { }; config = let - toConfig = attrs: concatStringsSep "\n" (mapAttrsToList toValue attrs); + toConfig = attrs: lib.concatStringsSep "\n" (lib.mapAttrsToList toValue attrs); toValue = name: value: - if isAttrs value - then pipe value [ - (mapAttrsToList toValue) + if lib.isAttrs value + then lib.pipe value [ + (lib.mapAttrsToList toValue) (map (s: " ${s}")) - (concatStringsSep "\n") + (lib.concatStringsSep "\n") (s: "${name} {\n${s}\n}") ] - else if isBool value - then "${name} = ${boolToString value}" - else if any (f: f value) [isString isInt isFloat] + else if lib.isBool value + then "${name} = ${lib.boolToString value}" + else if lib.any (f: f value) [lib.isString lib.isInt lib.isFloat] then "${name} = ${toString value}" else throw '' - Found invalid type in `services.watchdogd.settings`: '${typeOf value}' + Found invalid type in `services.watchdogd.settings`: '${lib.typeOf value}' ''; watchdogdConf = pkgs.writeText "watchdogd.conf" (toConfig cfg.settings); - in mkIf cfg.enable { + in lib.mkIf cfg.enable { environment.systemPackages = [ cfg.package ]; systemd.services.watchdogd = { @@ -127,5 +126,5 @@ in { }; }; - meta.maintainers = with maintainers; [ vifino ]; + meta.maintainers = with lib.maintainers; [ vifino ]; } From a9748cc11851d5c2cd44271291e930db04efde82 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:07 +0200 Subject: [PATCH 147/166] nixos/services.cachefilesd: remove `with lib;` --- .../network-filesystems/cachefilesd.nix | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-) diff --git a/nixos/modules/services/network-filesystems/cachefilesd.nix b/nixos/modules/services/network-filesystems/cachefilesd.nix index 8db0fdb8a417..b1c13cf41501 100644 --- a/nixos/modules/services/network-filesystems/cachefilesd.nix +++ b/nixos/modules/services/network-filesystems/cachefilesd.nix @@ -1,7 +1,4 @@ { config, pkgs, lib, ... }: - -with lib; - let cfg = config.services.cachefilesd; @@ -17,20 +14,20 @@ in options = { services.cachefilesd = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = "Whether to enable cachefilesd network filesystems caching daemon."; }; - cacheDir = mkOption { - type = types.str; + cacheDir = lib.mkOption { + type = lib.types.str; default = "/var/cache/fscache"; description = "Directory to contain filesystem cache."; }; - extraConfig = mkOption { - type = types.lines; + extraConfig = lib.mkOption { + type = lib.types.lines; default = ""; example = "brun 10%"; description = "Additional configuration file entries. See cachefilesd.conf(5) for more information."; @@ -41,7 +38,7 @@ in ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { boot.kernelModules = [ "cachefiles" ]; From 44985668d8340cbdced7a197fba52b60d3b6599b Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:08 +0200 Subject: [PATCH 148/166] nixos/services.diod: remove `with lib;` --- .../services/network-filesystems/diod.nix | 61 +++++++++---------- 1 file changed, 30 insertions(+), 31 deletions(-) diff --git a/nixos/modules/services/network-filesystems/diod.nix b/nixos/modules/services/network-filesystems/diod.nix index 063bae6ddb1d..8b3f4f9bd8c5 100644 --- a/nixos/modules/services/network-filesystems/diod.nix +++ b/nixos/modules/services/network-filesystems/diod.nix @@ -1,5 +1,4 @@ { config, lib, pkgs, ... }: -with lib; let cfg = config.services.diod; @@ -9,9 +8,9 @@ let allsquash = ${diodBool cfg.allsquash} auth_required = ${diodBool cfg.authRequired} exportall = ${diodBool cfg.exportall} - exportopts = "${concatStringsSep "," cfg.exportopts}" - exports = { ${concatStringsSep ", " (map (s: ''"${s}"'' ) cfg.exports)} } - listen = { ${concatStringsSep ", " (map (s: ''"${s}"'' ) cfg.listen)} } + exportopts = "${lib.concatStringsSep "," cfg.exportopts}" + exports = { ${lib.concatStringsSep ", " (map (s: ''"${s}"'' ) cfg.exports)} } + listen = { ${lib.concatStringsSep ", " (map (s: ''"${s}"'' ) cfg.listen)} } logdest = "${cfg.logdest}" nwthreads = ${toString cfg.nwthreads} squashuser = "${cfg.squashuser}" @@ -23,14 +22,14 @@ in { options = { services.diod = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = "Whether to enable the diod 9P file server."; }; - listen = mkOption { - type = types.listOf types.str; + listen = lib.mkOption { + type = lib.types.listOf lib.types.str; default = [ "0.0.0.0:564" ]; description = '' [ "IP:PORT" [,"IP:PORT",...] ] @@ -38,8 +37,8 @@ in ''; }; - exports = mkOption { - type = types.listOf types.str; + exports = lib.mkOption { + type = lib.types.listOf lib.types.str; default = []; description = '' List the file systems that clients will be allowed to mount. All paths should @@ -54,8 +53,8 @@ in ''; }; - exportall = mkOption { - type = types.bool; + exportall = lib.mkOption { + type = lib.types.bool; default = true; description = '' Export all file systems listed in /proc/mounts. If new file systems are mounted @@ -65,8 +64,8 @@ in ''; }; - exportopts = mkOption { - type = types.listOf types.str; + exportopts = lib.mkOption { + type = lib.types.listOf lib.types.str; default = []; description = '' Establish a default set of export options. These are overridden, not appended @@ -74,8 +73,8 @@ in ''; }; - nwthreads = mkOption { - type = types.int; + nwthreads = lib.mkOption { + type = lib.types.int; default = 16; description = '' Sets the (fixed) number of worker threads created to handle 9P @@ -83,16 +82,16 @@ in ''; }; - authRequired = mkOption { - type = types.bool; + authRequired = lib.mkOption { + type = lib.types.bool; default = false; description = '' Allow clients to connect without authentication, i.e. without a valid MUNGE credential. ''; }; - userdb = mkOption { - type = types.bool; + userdb = lib.mkOption { + type = lib.types.bool; default = false; description = '' This option disables password/group lookups. It allows any uid to attach and @@ -100,8 +99,8 @@ in ''; }; - allsquash = mkOption { - type = types.bool; + allsquash = lib.mkOption { + type = lib.types.bool; default = true; description = '' Remap all users to "nobody". The attaching user need not be present in the @@ -109,16 +108,16 @@ in ''; }; - squashuser = mkOption { - type = types.str; + squashuser = lib.mkOption { + type = lib.types.str; default = "nobody"; description = '' Change the squash user. The squash user must be present in the password file. ''; }; - logdest = mkOption { - type = types.str; + logdest = lib.mkOption { + type = lib.types.str; default = "syslog:daemon:err"; description = '' Set the destination for logging. @@ -127,8 +126,8 @@ in }; - statfsPassthru = mkOption { - type = types.bool; + statfsPassthru = lib.mkOption { + type = lib.types.bool; default = false; description = '' This option configures statfs to return the host file system's type @@ -136,15 +135,15 @@ in ''; }; - extraConfig = mkOption { - type = types.lines; + extraConfig = lib.mkOption { + type = lib.types.lines; default = ""; description = "Extra configuration options for diod.conf."; }; }; }; - config = mkIf config.services.diod.enable { + config = lib.mkIf config.services.diod.enable { environment.systemPackages = [ pkgs.diod ]; systemd.services.diod = { From 4dbf3a75ae486cddbb179ad0c678950a39ac3d11 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:08 +0200 Subject: [PATCH 149/166] nixos/services.drbd: remove `with lib;` --- .../modules/services/network-filesystems/drbd.nix | 14 +++++--------- 1 file changed, 5 insertions(+), 9 deletions(-) diff --git a/nixos/modules/services/network-filesystems/drbd.nix b/nixos/modules/services/network-filesystems/drbd.nix index b971fadebf71..2ecf8558a10f 100644 --- a/nixos/modules/services/network-filesystems/drbd.nix +++ b/nixos/modules/services/network-filesystems/drbd.nix @@ -1,9 +1,5 @@ # Support for DRBD, the Distributed Replicated Block Device. - { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.drbd; in { @@ -12,18 +8,18 @@ let cfg = config.services.drbd; in options = { - services.drbd.enable = mkOption { + services.drbd.enable = lib.mkOption { default = false; - type = types.bool; + type = lib.types.bool; description = '' Whether to enable support for DRBD, the Distributed Replicated Block Device. ''; }; - services.drbd.config = mkOption { + services.drbd.config = lib.mkOption { default = ""; - type = types.lines; + type = lib.types.lines; description = '' Contents of the {file}`drbd.conf` configuration file. ''; @@ -34,7 +30,7 @@ let cfg = config.services.drbd; in ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = [ pkgs.drbd ]; From e4ffb753b1c992132247a2bb4ed06a9fc4066660 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:08 +0200 Subject: [PATCH 150/166] nixos/services.glusterfs: remove `with lib;` --- .../network-filesystems/glusterfs.nix | 53 +++++++++---------- 1 file changed, 25 insertions(+), 28 deletions(-) diff --git a/nixos/modules/services/network-filesystems/glusterfs.nix b/nixos/modules/services/network-filesystems/glusterfs.nix index f23e2842f3a8..d34370875f6b 100644 --- a/nixos/modules/services/network-filesystems/glusterfs.nix +++ b/nixos/modules/services/network-filesystems/glusterfs.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let inherit (pkgs) glusterfs rsync; @@ -15,7 +12,7 @@ let rm -f /var/lib/glusterd/secure-access ''; - restartTriggers = optionals (cfg.tlsSettings != null) [ + restartTriggers = lib.optionals (cfg.tlsSettings != null) [ config.environment.etc."ssl/glusterfs.pem".source config.environment.etc."ssl/glusterfs.key".source config.environment.etc."ssl/glusterfs.ca".source @@ -33,16 +30,16 @@ in services.glusterfs = { - enable = mkEnableOption "GlusterFS Daemon"; + enable = lib.mkEnableOption "GlusterFS Daemon"; - logLevel = mkOption { - type = types.enum ["DEBUG" "INFO" "WARNING" "ERROR" "CRITICAL" "TRACE" "NONE"]; + logLevel = lib.mkOption { + type = lib.types.enum ["DEBUG" "INFO" "WARNING" "ERROR" "CRITICAL" "TRACE" "NONE"]; description = "Log level used by the GlusterFS daemon"; default = "INFO"; }; - useRpcbind = mkOption { - type = types.bool; + useRpcbind = lib.mkOption { + type = lib.types.bool; description = '' Enable use of rpcbind. This is required for Gluster's NFS functionality. @@ -54,14 +51,14 @@ in default = true; }; - enableGlustereventsd = mkOption { - type = types.bool; + enableGlustereventsd = lib.mkOption { + type = lib.types.bool; description = "Whether to enable the GlusterFS Events Daemon"; default = true; }; - killMode = mkOption { - type = types.enum ["control-group" "process" "mixed" "none"]; + killMode = lib.mkOption { + type = lib.types.enum ["control-group" "process" "mixed" "none"]; description = '' The systemd KillMode to use for glusterd. @@ -77,8 +74,8 @@ in default = "control-group"; }; - stopKillTimeout = mkOption { - type = types.str; + stopKillTimeout = lib.mkOption { + type = lib.types.str; description = '' The systemd TimeoutStopSec to use. @@ -92,13 +89,13 @@ in default = "5s"; }; - extraFlags = mkOption { - type = types.listOf types.str; + extraFlags = lib.mkOption { + type = lib.types.listOf lib.types.str; description = "Extra flags passed to the GlusterFS daemon"; default = []; }; - tlsSettings = mkOption { + tlsSettings = lib.mkOption { description = '' Make the server communicate via TLS. This means it will only connect to other gluster @@ -110,20 +107,20 @@ in See also: https://gluster.readthedocs.io/en/latest/Administrator%20Guide/SSL/ ''; default = null; - type = types.nullOr (types.submodule { + type = lib.types.nullOr (lib.types.submodule { options = { - tlsKeyPath = mkOption { - type = types.str; + tlsKeyPath = lib.mkOption { + type = lib.types.str; description = "Path to the private key used for TLS."; }; - tlsPem = mkOption { - type = types.path; + tlsPem = lib.mkOption { + type = lib.types.path; description = "Path to the certificate used for TLS."; }; - caCert = mkOption { - type = types.path; + caCert = lib.mkOption { + type = lib.types.path; description = "Path certificate authority used to sign the cluster certificates."; }; }; @@ -134,12 +131,12 @@ in ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { environment.systemPackages = [ pkgs.glusterfs ]; services.rpcbind.enable = cfg.useRpcbind; - environment.etc = mkIf (cfg.tlsSettings != null) { + environment.etc = lib.mkIf (cfg.tlsSettings != null) { "ssl/glusterfs.pem".source = cfg.tlsSettings.tlsPem; "ssl/glusterfs.key".source = cfg.tlsSettings.tlsKeyPath; "ssl/glusterfs.ca".source = cfg.tlsSettings.caCert; @@ -181,7 +178,7 @@ in }; }; - systemd.services.glustereventsd = mkIf cfg.enableGlustereventsd { + systemd.services.glustereventsd = lib.mkIf cfg.enableGlustereventsd { inherit restartTriggers; description = "Gluster Events Notifier"; From e14d1dc1986e9637930eb7f08be2e74e3cb7113e Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:08 +0200 Subject: [PATCH 151/166] nixos/services.ncdns: remove `with lib;` --- nixos/modules/services/networking/ncdns.nix | 73 ++++++++++----------- 1 file changed, 35 insertions(+), 38 deletions(-) diff --git a/nixos/modules/services/networking/ncdns.nix b/nixos/modules/services/networking/ncdns.nix index d9aeb29e285f..115726381eb7 100644 --- a/nixos/modules/services/networking/ncdns.nix +++ b/nixos/modules/services/networking/ncdns.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfgs = config.services; cfg = cfgs.ncdns; @@ -9,10 +6,10 @@ let dataDir = "/var/lib/ncdns"; username = "ncdns"; - valueType = with types; oneOf [ int str bool path ] + valueType = with lib.types; oneOf [ int str bool path ] // { description = "setting type (integer, string, bool or path)"; }; - configType = with types; attrsOf (nullOr (either valueType configType)) + configType = with lib.types; attrsOf (nullOr (either valueType configType)) // { description = '' ncdns.conf configuration type. The format consists of an attribute set of settings. Each setting can be either `null`, @@ -35,10 +32,10 @@ let }; # if all keys are the default value - needsKeygen = all id (flip mapAttrsToList cfg.dnssec.keys - (n: v: v == getAttr n defaultFiles)); + needsKeygen = lib.all lib.id (lib.flip lib.mapAttrsToList cfg.dnssec.keys + (n: v: v == lib.getAttr n defaultFiles)); - mkDefaultAttrs = mapAttrs (n: v: mkDefault v); + mkDefaultAttrs = lib.mapAttrs (n: v: lib.mkDefault v); in @@ -50,14 +47,14 @@ in services.ncdns = { - enable = mkEnableOption '' + enable = lib.mkEnableOption '' ncdns, a Go daemon to bridge Namecoin to DNS. To resolve .bit domains set `services.namecoind.enable = true;` and an RPC username/password ''; - address = mkOption { - type = types.str; + address = lib.mkOption { + type = lib.types.str; default = "[::1]"; description = '' The IP address the ncdns resolver will bind to. Leave this unchanged @@ -65,18 +62,18 @@ in ''; }; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 5333; description = '' The port the ncdns resolver will bind to. ''; }; - identity.hostname = mkOption { - type = types.str; + identity.hostname = lib.mkOption { + type = lib.types.str; default = config.networking.hostName; - defaultText = literalExpression "config.networking.hostName"; + defaultText = lib.literalExpression "config.networking.hostName"; example = "example.com"; description = '' The hostname of this ncdns instance, which defaults to the machine @@ -92,8 +89,8 @@ in ''; }; - identity.hostmaster = mkOption { - type = types.str; + identity.hostmaster = lib.mkOption { + type = lib.types.str; default = ""; example = "root@example.com"; description = '' @@ -102,8 +99,8 @@ in ''; }; - identity.address = mkOption { - type = types.str; + identity.address = lib.mkOption { + type = lib.types.str; default = "127.127.127.127"; description = '' The IP address the hostname specified in @@ -112,7 +109,7 @@ in ''; }; - dnssec.enable = mkEnableOption '' + dnssec.enable = lib.mkEnableOption '' DNSSEC support in ncdns. This will generate KSK and ZSK keypairs (unless provided via the options {option}`services.ncdns.dnssec.publicKey`, @@ -120,8 +117,8 @@ in anchor to recursive resolvers ''; - dnssec.keys.public = mkOption { - type = types.path; + dnssec.keys.public = lib.mkOption { + type = lib.types.path; default = defaultFiles.public; description = '' Path to the file containing the KSK public key. @@ -133,16 +130,16 @@ in ''; }; - dnssec.keys.private = mkOption { - type = types.path; + dnssec.keys.private = lib.mkOption { + type = lib.types.path; default = defaultFiles.private; description = '' Path to the file containing the KSK private key. ''; }; - dnssec.keys.zonePublic = mkOption { - type = types.path; + dnssec.keys.zonePublic = lib.mkOption { + type = lib.types.path; default = defaultFiles.zonePublic; description = '' Path to the file containing the ZSK public key. @@ -154,18 +151,18 @@ in ''; }; - dnssec.keys.zonePrivate = mkOption { - type = types.path; + dnssec.keys.zonePrivate = lib.mkOption { + type = lib.types.path; default = defaultFiles.zonePrivate; description = '' Path to the file containing the ZSK private key. ''; }; - settings = mkOption { + settings = lib.mkOption { type = configType; default = { }; - example = literalExpression '' + example = lib.literalExpression '' { # enable webserver ncdns.httplistenaddr = ":8202"; @@ -186,8 +183,8 @@ in }; - services.pdns-recursor.resolveNamecoin = mkOption { - type = types.bool; + services.pdns-recursor.resolveNamecoin = lib.mkOption { + type = lib.types.bool; default = false; description = '' Resolve `.bit` top-level domains using ncdns and namecoin. @@ -199,9 +196,9 @@ in ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { - services.pdns-recursor = mkIf cfgs.pdns-recursor.resolveNamecoin { + services.pdns-recursor = lib.mkIf cfgs.pdns-recursor.resolveNamecoin { forwardZonesRecurse.bit = "${cfg.address}:${toString cfg.port}"; luaConfig = if cfg.dnssec.enable @@ -210,7 +207,7 @@ in }; # Avoid pdns-recursor not finding the DNSSEC keys - systemd.services.pdns-recursor = mkIf cfgs.pdns-recursor.resolveNamecoin { + systemd.services.pdns-recursor = lib.mkIf cfgs.pdns-recursor.resolveNamecoin { after = [ "ncdns.service" ]; wants = [ "ncdns.service" ]; }; @@ -231,7 +228,7 @@ in # Other bind = "${cfg.address}:${toString cfg.port}"; } - // optionalAttrs cfg.dnssec.enable + // lib.optionalAttrs cfg.dnssec.enable { # DNSSEC publickey = "../.." + cfg.dnssec.keys.public; privatekey = "../.." + cfg.dnssec.keys.private; @@ -263,7 +260,7 @@ in ExecStart = "${pkgs.ncdns}/bin/ncdns -conf=${configFile}"; }; - preStart = optionalString (cfg.dnssec.enable && needsKeygen) '' + preStart = lib.optionalString (cfg.dnssec.enable && needsKeygen) '' cd ${dataDir} if [ ! -e bit.key ]; then ${pkgs.bind}/bin/dnssec-keygen -a RSASHA256 -3 -b 2048 bit From 83cc2cd01fd4ef7a3fb7a4fb3e209dfe0b1a392b Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:08 +0200 Subject: [PATCH 152/166] nixos/services.nebula: remove `with lib;` --- nixos/modules/services/networking/nebula.nix | 91 ++++++++++---------- 1 file changed, 44 insertions(+), 47 deletions(-) diff --git a/nixos/modules/services/networking/nebula.nix b/nixos/modules/services/networking/nebula.nix index 477731f3f5a4..2ddad4e4094c 100644 --- a/nixos/modules/services/networking/nebula.nix +++ b/nixos/modules/services/networking/nebula.nix @@ -1,11 +1,8 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.nebula; - enabledNetworks = filterAttrs (n: v: v.enable) cfg.networks; + enabledNetworks = lib.filterAttrs (n: v: v.enable) cfg.networks; format = pkgs.formats.yaml {}; @@ -25,39 +22,39 @@ in options = { services.nebula = { - networks = mkOption { + networks = lib.mkOption { description = "Nebula network definitions."; default = {}; - type = types.attrsOf (types.submodule { + type = lib.types.attrsOf (lib.types.submodule { options = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = true; description = "Enable or disable this network."; }; - package = mkPackageOption pkgs "nebula" { }; + package = lib.mkPackageOption pkgs "nebula" { }; - ca = mkOption { - type = types.path; + ca = lib.mkOption { + type = lib.types.path; description = "Path to the certificate authority certificate."; example = "/etc/nebula/ca.crt"; }; - cert = mkOption { - type = types.path; + cert = lib.mkOption { + type = lib.types.path; description = "Path to the host certificate."; example = "/etc/nebula/host.crt"; }; - key = mkOption { - type = types.oneOf [types.nonEmptyStr types.path]; + key = lib.mkOption { + type = lib.types.oneOf [lib.types.nonEmptyStr lib.types.path]; description = "Path or reference to the host key."; example = "/etc/nebula/host.key"; }; - staticHostMap = mkOption { - type = types.attrsOf (types.listOf (types.str)); + staticHostMap = lib.mkOption { + type = lib.types.attrsOf (lib.types.listOf (lib.types.str)); default = {}; description = '' The static host map defines a set of hosts with fixed IP addresses on the internet (or any network). @@ -66,20 +63,20 @@ in example = { "192.168.100.1" = [ "100.64.22.11:4242" ]; }; }; - isLighthouse = mkOption { - type = types.bool; + isLighthouse = lib.mkOption { + type = lib.types.bool; default = false; description = "Whether this node is a lighthouse."; }; - isRelay = mkOption { - type = types.bool; + isRelay = lib.mkOption { + type = lib.types.bool; default = false; description = "Whether this node is a relay."; }; - lighthouses = mkOption { - type = types.listOf types.str; + lighthouses = lib.mkOption { + type = lib.types.listOf lib.types.str; default = []; description = '' List of IPs of lighthouse hosts this node should report to and query from. This should be empty on lighthouse @@ -88,8 +85,8 @@ in example = [ "192.168.100.1" ]; }; - relays = mkOption { - type = types.listOf types.str; + relays = lib.mkOption { + type = lib.types.listOf lib.types.str; default = []; description = '' List of IPs of relays that this node should allow traffic from. @@ -97,14 +94,14 @@ in example = [ "192.168.100.1" ]; }; - listen.host = mkOption { - type = types.str; + listen.host = lib.mkOption { + type = lib.types.str; default = "0.0.0.0"; description = "IP address to listen on."; }; - listen.port = mkOption { - type = types.nullOr types.port; + listen.port = lib.mkOption { + type = lib.types.nullOr lib.types.port; default = null; defaultText = lib.literalExpression '' if (config.services.nebula.networks.''${name}.isLighthouse || @@ -116,35 +113,35 @@ in description = "Port number to listen on."; }; - tun.disable = mkOption { - type = types.bool; + tun.disable = lib.mkOption { + type = lib.types.bool; default = false; description = '' When tun is disabled, a lighthouse can be started without a local tun interface (and therefore without root). ''; }; - tun.device = mkOption { - type = types.nullOr types.str; + tun.device = lib.mkOption { + type = lib.types.nullOr lib.types.str; default = null; description = "Name of the tun device. Defaults to nebula.\${networkName}."; }; - firewall.outbound = mkOption { - type = types.listOf types.attrs; + firewall.outbound = lib.mkOption { + type = lib.types.listOf lib.types.attrs; default = []; description = "Firewall rules for outbound traffic."; example = [ { port = "any"; proto = "any"; host = "any"; } ]; }; - firewall.inbound = mkOption { - type = types.listOf types.attrs; + firewall.inbound = lib.mkOption { + type = lib.types.listOf lib.types.attrs; default = []; description = "Firewall rules for inbound traffic."; example = [ { port = "any"; proto = "any"; host = "any"; } ]; }; - settings = mkOption { + settings = lib.mkOption { type = format.type; default = {}; description = '' @@ -152,7 +149,7 @@ in for details on supported values. ''; - example = literalExpression '' + example = lib.literalExpression '' { lighthouse.dns = { host = "0.0.0.0"; @@ -168,11 +165,11 @@ in }; # Implementation - config = mkIf (enabledNetworks != {}) { - systemd.services = mkMerge (mapAttrsToList (netName: netCfg: + config = lib.mkIf (enabledNetworks != {}) { + systemd.services = lib.mkMerge (lib.mapAttrsToList (netName: netCfg: let networkId = nameToId netName; - settings = recursiveUpdate { + settings = lib.recursiveUpdate { pki = { ca = netCfg.ca; cert = netCfg.cert; @@ -202,7 +199,7 @@ in }; } netCfg.settings; configFile = format.generate "nebula-config-${netName}.yml" ( - warnIf + lib.warnIf ((settings.lighthouse.am_lighthouse || settings.relay.am_relay) && settings.listen.port == 0) '' Nebula network '${netName}' is configured as a lighthouse or relay, and its port is ${builtins.toString settings.listen.port}. @@ -253,10 +250,10 @@ in # Open the chosen ports for UDP. networking.firewall.allowedUDPPorts = - unique (filter (port: port > 0) (mapAttrsToList (netName: netCfg: resolveFinalPort netCfg) enabledNetworks)); + lib.unique (lib.filter (port: port > 0) (lib.mapAttrsToList (netName: netCfg: resolveFinalPort netCfg) enabledNetworks)); # Create the service users and groups. - users.users = mkMerge (mapAttrsToList (netName: netCfg: + users.users = lib.mkMerge (lib.mapAttrsToList (netName: netCfg: { ${nameToId netName} = { group = nameToId netName; @@ -265,10 +262,10 @@ in }; }) enabledNetworks); - users.groups = mkMerge (mapAttrsToList (netName: netCfg: { + users.groups = lib.mkMerge (lib.mapAttrsToList (netName: netCfg: { ${nameToId netName} = {}; }) enabledNetworks); }; - meta.maintainers = with maintainers; [ numinit ]; + meta.maintainers = with lib.maintainers; [ numinit ]; } From 2bf4393a9b32ce286117c0a800d2ffb6a5851a6a Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:09 +0200 Subject: [PATCH 153/166] nixos/networking.nftables: remove `with lib;` --- .../modules/services/networking/nftables.nix | 71 +++++++++---------- 1 file changed, 35 insertions(+), 36 deletions(-) diff --git a/nixos/modules/services/networking/nftables.nix b/nixos/modules/services/networking/nftables.nix index ada9b83716a5..0c1725f12b3d 100644 --- a/nixos/modules/services/networking/nftables.nix +++ b/nixos/modules/services/networking/nftables.nix @@ -1,34 +1,33 @@ { config, pkgs, lib, ... }: -with lib; let cfg = config.networking.nftables; tableSubmodule = { name, ... }: { options = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = true; description = "Enable this table."; }; - name = mkOption { - type = types.str; + name = lib.mkOption { + type = lib.types.str; description = "Table name."; }; - content = mkOption { - type = types.lines; + content = lib.mkOption { + type = lib.types.lines; description = "The table content."; }; - family = mkOption { + family = lib.mkOption { description = "Table family."; - type = types.enum [ "ip" "ip6" "inet" "arp" "bridge" "netdev" ]; + type = lib.types.enum [ "ip" "ip6" "inet" "arp" "bridge" "netdev" ]; }; }; config = { - name = mkDefault name; + name = lib.mkDefault name; }; }; in @@ -36,8 +35,8 @@ in ###### interface options = { - networking.nftables.enable = mkOption { - type = types.bool; + networking.nftables.enable = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether to enable nftables and use nftables based firewall if enabled. @@ -57,8 +56,8 @@ in ''; }; - networking.nftables.checkRuleset = mkOption { - type = types.bool; + networking.nftables.checkRuleset = lib.mkOption { + type = lib.types.bool; default = true; description = '' Run `nft check` on the ruleset to spot syntax errors during build. @@ -69,14 +68,14 @@ in ''; }; - networking.nftables.checkRulesetRedirects = mkOption { - type = types.addCheck (types.attrsOf types.path) (attrs: all types.path.check (attrNames attrs)); + networking.nftables.checkRulesetRedirects = lib.mkOption { + type = lib.types.addCheck (lib.types.attrsOf lib.types.path) (attrs: lib.all lib.types.path.check (lib.attrNames attrs)); default = { "/etc/hosts" = config.environment.etc.hosts.source; "/etc/protocols" = config.environment.etc.protocols.source; "/etc/services" = config.environment.etc.services.source; }; - defaultText = literalExpression '' + defaultText = lib.literalExpression '' { "/etc/hosts" = config.environment.etc.hosts.source; "/etc/protocols" = config.environment.etc.protocols.source; @@ -89,8 +88,8 @@ in ''; }; - networking.nftables.preCheckRuleset = mkOption { - type = types.lines; + networking.nftables.preCheckRuleset = lib.mkOption { + type = lib.types.lines; default = ""; example = lib.literalExpression '' sed 's/skgid meadow/skgid nogroup/g' -i ruleset.conf @@ -102,10 +101,10 @@ in ''; }; - networking.nftables.flushRuleset = mkEnableOption "flushing the entire ruleset on each reload"; + networking.nftables.flushRuleset = lib.mkEnableOption "flushing the entire ruleset on each reload"; - networking.nftables.extraDeletions = mkOption { - type = types.lines; + networking.nftables.extraDeletions = lib.mkOption { + type = lib.types.lines; default = ""; example = '' # this makes deleting a non-existing table a no-op instead of an error @@ -119,8 +118,8 @@ in ''; }; - networking.nftables.ruleset = mkOption { - type = types.lines; + networking.nftables.ruleset = lib.mkOption { + type = lib.types.lines; default = ""; example = '' # Check out https://wiki.nftables.org/ for better documentation. @@ -173,8 +172,8 @@ in - or networking.nftables.tables can be used, which will clean up the table automatically ''; }; - networking.nftables.rulesetFile = mkOption { - type = types.nullOr types.path; + networking.nftables.rulesetFile = lib.mkOption { + type = lib.types.nullOr lib.types.path; default = null; description = '' The ruleset file to be used with nftables. Should be in a format that @@ -182,8 +181,8 @@ in ''; }; - networking.nftables.flattenRulesetFile = mkOption { - type = types.bool; + networking.nftables.flattenRulesetFile = lib.mkOption { + type = lib.types.bool; default = false; description = '' Use `builtins.readFile` rather than `include` to handle {option}`networking.nftables.rulesetFile`. It is useful when you want to apply {option}`networking.nftables.preCheckRuleset` to {option}`networking.nftables.rulesetFile`. @@ -194,8 +193,8 @@ in ''; }; - networking.nftables.tables = mkOption { - type = types.attrsOf (types.submodule tableSubmodule); + networking.nftables.tables = lib.mkOption { + type = lib.types.attrsOf (lib.types.submodule tableSubmodule); default = {}; @@ -254,11 +253,11 @@ in ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { boot.blacklistedKernelModules = [ "ip_tables" ]; environment.systemPackages = [ pkgs.nftables ]; # versionOlder for backportability, remove afterwards - networking.nftables.flushRuleset = mkDefault (versionOlder config.system.stateVersion "23.11" || (cfg.rulesetFile != null || cfg.ruleset != "")); + networking.nftables.flushRuleset = lib.mkDefault (lib.versionOlder config.system.stateVersion "23.11" || (cfg.rulesetFile != null || cfg.ruleset != "")); systemd.services.nftables = { description = "nftables firewall"; after = [ "sysinit.target" ]; @@ -268,11 +267,11 @@ in wantedBy = [ "multi-user.target" ]; reloadIfChanged = true; serviceConfig = let - enabledTables = filterAttrs (_: table: table.enable) cfg.tables; + enabledTables = lib.filterAttrs (_: table: table.enable) cfg.tables; deletionsScript = pkgs.writeScript "nftables-deletions" '' #! ${pkgs.nftables}/bin/nft -f ${if cfg.flushRuleset then "flush ruleset" - else concatStringsSep "\n" (mapAttrsToList (_: table: '' + else lib.concatStringsSep "\n" (lib.mapAttrsToList (_: table: '' table ${table.family} ${table.name} delete table ${table.family} ${table.name} '') enabledTables)} @@ -298,7 +297,7 @@ in include "${deletionsScriptVar}" # current deletions include "${deletionsScript}" - ${concatStringsSep "\n" (mapAttrsToList (_: table: '' + ${lib.concatStringsSep "\n" (lib.mapAttrsToList (_: table: '' table ${table.family} ${table.name} { ${table.content} } @@ -316,7 +315,7 @@ in cp $out ruleset.conf sed 's|include "${deletionsScriptVar}"||' -i ruleset.conf ${cfg.preCheckRuleset} - export NIX_REDIRECTS=${escapeShellArg (concatStringsSep ":" (mapAttrsToList (n: v: "${n}=${v}") cfg.checkRulesetRedirects))} + export NIX_REDIRECTS=${lib.escapeShellArg (lib.concatStringsSep ":" (lib.mapAttrsToList (n: v: "${n}=${v}") cfg.checkRulesetRedirects))} LD_PRELOAD="${pkgs.buildPackages.libredirect}/lib/libredirect.so ${pkgs.buildPackages.lklWithFirewall.lib}/lib/liblkl-hijack.so" \ ${pkgs.buildPackages.nftables}/bin/nft --check --file ruleset.conf ''; From 2d4a4c110ab0d1bd40c0e148b898a2e126996e82 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:09 +0200 Subject: [PATCH 154/166] nixos/services.nylon: remove `with lib;` --- nixos/modules/services/networking/nylon.nix | 61 ++++++++++----------- 1 file changed, 29 insertions(+), 32 deletions(-) diff --git a/nixos/modules/services/networking/nylon.nix b/nixos/modules/services/networking/nylon.nix index f1b9abf61d60..2e5399a05c3c 100644 --- a/nixos/modules/services/networking/nylon.nix +++ b/nixos/modules/services/networking/nylon.nix @@ -1,7 +1,4 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.nylon; @@ -18,78 +15,78 @@ let Binding-Interface=${cfg.acceptInterface} Connecting-Interface=${cfg.bindInterface} Port=${toString cfg.port} - Allow-IP=${concatStringsSep " " cfg.allowedIPRanges} - Deny-IP=${concatStringsSep " " cfg.deniedIPRanges} + Allow-IP=${lib.concatStringsSep " " cfg.allowedIPRanges} + Deny-IP=${lib.concatStringsSep " " cfg.deniedIPRanges} ''; nylonOpts = { name, ... }: { options = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = '' Enables nylon as a running service upon activation. ''; }; - name = mkOption { - type = types.str; + name = lib.mkOption { + type = lib.types.str; default = ""; description = "The name of this nylon instance."; }; - nrConnections = mkOption { - type = types.int; + nrConnections = lib.mkOption { + type = lib.types.int; default = 10; description = '' The number of allowed simultaneous connections to the daemon, default 10. ''; }; - logging = mkOption { - type = types.bool; + logging = lib.mkOption { + type = lib.types.bool; default = false; description = '' Enable logging, default is no logging. ''; }; - verbosity = mkOption { - type = types.bool; + verbosity = lib.mkOption { + type = lib.types.bool; default = false; description = '' Enable verbose output, default is to not be verbose. ''; }; - acceptInterface = mkOption { - type = types.str; + acceptInterface = lib.mkOption { + type = lib.types.str; default = "lo"; description = '' Tell nylon which interface to listen for client requests on, default is "lo". ''; }; - bindInterface = mkOption { - type = types.str; + bindInterface = lib.mkOption { + type = lib.types.str; default = "enp3s0f0"; description = '' Tell nylon which interface to use as an uplink, default is "enp3s0f0". ''; }; - port = mkOption { - type = types.port; + port = lib.mkOption { + type = lib.types.port; default = 1080; description = '' What port to listen for client requests, default is 1080. ''; }; - allowedIPRanges = mkOption { - type = with types; listOf str; + allowedIPRanges = lib.mkOption { + type = with lib.types; listOf str; default = [ "192.168.0.0/16" "127.0.0.1/8" "172.16.0.1/12" "10.0.0.0/8" ]; description = '' Allowed client IP ranges are evaluated first, defaults to ARIN IPv4 private ranges: @@ -97,8 +94,8 @@ let ''; }; - deniedIPRanges = mkOption { - type = with types; listOf str; + deniedIPRanges = lib.mkOption { + type = with lib.types; listOf str; default = [ "0.0.0.0/0" ]; description = '' Denied client IP ranges, these gets evaluated after the allowed IP ranges, defaults to all IPv4 addresses: @@ -107,7 +104,7 @@ let ''; }; }; - config = { name = mkDefault name; }; + config = { name = lib.mkDefault name; }; }; mkNamedNylon = cfg: { @@ -125,8 +122,8 @@ let }; }; - anyNylons = collect (p: p ? enable) cfg; - enabledNylons = filter (p: p.enable == true) anyNylons; + anyNylons = lib.collect (p: p ? enable) cfg; + enabledNylons = lib.filter (p: p.enable == true) anyNylons; nylonUnits = map (nylon: mkNamedNylon nylon) enabledNylons; in @@ -137,10 +134,10 @@ in options = { - services.nylon = mkOption { + services.nylon = lib.mkOption { default = {}; description = "Collection of named nylon instances"; - type = with types; attrsOf (submodule nylonOpts); + type = with lib.types; attrsOf (submodule nylonOpts); internal = true; }; @@ -148,7 +145,7 @@ in ###### implementation - config = mkIf (length(enabledNylons) > 0) { + config = lib.mkIf (lib.length(enabledNylons) > 0) { users.users.nylon = { group = "nylon"; @@ -160,7 +157,7 @@ in users.groups.nylon.gid = config.ids.gids.nylon; - systemd.services = foldr (a: b: a // b) {} nylonUnits; + systemd.services = lib.foldr (a: b: a // b) {} nylonUnits; }; } From 93d6b8180e0ceb2c856975e4ea8e2d170c919b49 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:09 +0200 Subject: [PATCH 155/166] nixos/services.oink: remove `with lib;` --- nixos/modules/services/networking/oink.nix | 31 ++++++++++------------ 1 file changed, 14 insertions(+), 17 deletions(-) diff --git a/nixos/modules/services/networking/oink.nix b/nixos/modules/services/networking/oink.nix index 3497ca9220a8..7954cbed709d 100644 --- a/nixos/modules/services/networking/oink.nix +++ b/nixos/modules/services/networking/oink.nix @@ -1,11 +1,8 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.oink; makeOinkConfig = attrs: (pkgs.formats.json { }).generate - "oink.json" (mapAttrs' (k: v: nameValuePair (toLower k) v) attrs); + "oink.json" (lib.mapAttrs' (k: v: lib.nameValuePair (lib.toLower k) v) attrs); oinkConfig = makeOinkConfig { global = cfg.settings; domains = cfg.domains; @@ -13,25 +10,25 @@ let in { options.services.oink = { - enable = mkEnableOption "Oink, a dynamic DNS client for Porkbun"; - package = mkPackageOption pkgs "oink" { }; + enable = lib.mkEnableOption "Oink, a dynamic DNS client for Porkbun"; + package = lib.mkPackageOption pkgs "oink" { }; settings = { - apiKey = mkOption { - type = types.str; + apiKey = lib.mkOption { + type = lib.types.str; description = "API key to use when modifying DNS records."; }; - secretApiKey = mkOption { - type = types.str; + secretApiKey = lib.mkOption { + type = lib.types.str; description = "Secret API key to use when modifying DNS records."; }; - interval = mkOption { + interval = lib.mkOption { # https://github.com/rlado/oink/blob/v1.1.1/src/main.go#L364 - type = types.ints.between 60 172800; # 48 hours + type = lib.types.ints.between 60 172800; # 48 hours default = 900; description = "Seconds to wait before sending another request."; }; - ttl = mkOption { - type = types.ints.between 600 172800; + ttl = lib.mkOption { + type = lib.types.ints.between 600 172800; default = 600; description = '' The TTL ("Time to Live") value to set for your DNS records. @@ -41,8 +38,8 @@ in ''; }; }; - domains = mkOption { - type = with types; listOf (attrsOf anything); + domains = lib.mkOption { + type = with lib.types; listOf (attrsOf anything); default = []; example = [ { @@ -74,7 +71,7 @@ in }; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { systemd.services.oink = { description = "Dynamic DNS client for Porkbun"; after = [ "network.target" ]; From 07894f4f304c7708e81031a7ea5df5233693ce2c Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Fri, 30 Aug 2024 00:47:10 +0200 Subject: [PATCH 156/166] nixos/services.stunnel: remove `with lib;` --- nixos/modules/services/networking/stunnel.nix | 77 +++++++++---------- 1 file changed, 37 insertions(+), 40 deletions(-) diff --git a/nixos/modules/services/networking/stunnel.nix b/nixos/modules/services/networking/stunnel.nix index 9f9068c8e077..da308dde8b26 100644 --- a/nixos/modules/services/networking/stunnel.nix +++ b/nixos/modules/services/networking/stunnel.nix @@ -1,14 +1,11 @@ { config, lib, pkgs, ... }: - -with lib; - let cfg = config.services.stunnel; yesNo = val: if val then "yes" else "no"; verifyRequiredField = type: field: n: c: { - assertion = hasAttr field c; + assertion = lib.hasAttr field c; message = "stunnel: \"${n}\" ${type} configuration - Field ${field} is required."; }; @@ -18,14 +15,14 @@ let "is not possible without either verifyChain or verifyPeer enabled"; }; - removeNulls = mapAttrs (_: filterAttrs (_: v: v != null)); + removeNulls = lib.mapAttrs (_: lib.filterAttrs (_: v: v != null)); mkValueString = v: if v == true then "yes" else if v == false then "no" - else generators.mkValueStringDefault {} v; + else lib.generators.mkValueStringDefault {} v; generateConfig = c: - generators.toINI { - mkSectionName = id; + lib.generators.toINI { + mkSectionName = lib.id; mkKeyValue = k: v: "${k} = ${mkValueString v}"; } (removeNulls c); @@ -39,50 +36,50 @@ in services.stunnel = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = "Whether to enable the stunnel TLS tunneling service."; }; - user = mkOption { - type = with types; nullOr str; + user = lib.mkOption { + type = with lib.types; nullOr str; default = "nobody"; description = "The user under which stunnel runs."; }; - group = mkOption { - type = with types; nullOr str; + group = lib.mkOption { + type = with lib.types; nullOr str; default = "nogroup"; description = "The group under which stunnel runs."; }; - logLevel = mkOption { - type = types.enum [ "emerg" "alert" "crit" "err" "warning" "notice" "info" "debug" ]; + logLevel = lib.mkOption { + type = lib.types.enum [ "emerg" "alert" "crit" "err" "warning" "notice" "info" "debug" ]; default = "info"; description = "Verbosity of stunnel output."; }; - fipsMode = mkOption { - type = types.bool; + fipsMode = lib.mkOption { + type = lib.types.bool; default = false; description = "Enable FIPS 140-2 mode required for compliance."; }; - enableInsecureSSLv3 = mkOption { - type = types.bool; + enableInsecureSSLv3 = lib.mkOption { + type = lib.types.bool; default = false; description = "Enable support for the insecure SSLv3 protocol."; }; - servers = mkOption { + servers = lib.mkOption { description = '' Define the server configurations. See "SERVICE-LEVEL OPTIONS" in {manpage}`stunnel(8)`. ''; - type = with types; attrsOf (attrsOf (nullOr (oneOf [bool int str]))); + type = with lib.types; attrsOf (attrsOf (nullOr (oneOf [bool int str]))); example = { fancyWebserver = { accept = 443; @@ -93,7 +90,7 @@ in default = { }; }; - clients = mkOption { + clients = lib.mkOption { description = '' Define the client configurations. @@ -101,7 +98,7 @@ in See "SERVICE-LEVEL OPTIONS" in {manpage}`stunnel(8)`. ''; - type = with types; attrsOf (attrsOf (nullOr (oneOf [bool int str]))); + type = with lib.types; attrsOf (attrsOf (nullOr (oneOf [bool int str]))); apply = let applyDefaults = c: @@ -118,7 +115,7 @@ in verifyHostname = null; # Not a real stunnel configuration setting }; forceClient = c: c // { client = true; }; - in mapAttrs (_: c: forceClient (setCheckHostFromVerifyHostname (applyDefaults c))); + in lib.mapAttrs (_: c: forceClient (setCheckHostFromVerifyHostname (applyDefaults c))); example = { foobar = { @@ -135,32 +132,32 @@ in ###### implementation - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { - assertions = concatLists [ - (singleton { - assertion = (length (attrValues cfg.servers) != 0) || ((length (attrValues cfg.clients)) != 0); + assertions = lib.concatLists [ + (lib.singleton { + assertion = (lib.length (lib.attrValues cfg.servers) != 0) || ((lib.length (lib.attrValues cfg.clients)) != 0); message = "stunnel: At least one server- or client-configuration has to be present."; }) - (mapAttrsToList verifyChainPathAssert cfg.clients) - (mapAttrsToList (verifyRequiredField "client" "accept") cfg.clients) - (mapAttrsToList (verifyRequiredField "client" "connect") cfg.clients) - (mapAttrsToList (verifyRequiredField "server" "accept") cfg.servers) - (mapAttrsToList (verifyRequiredField "server" "cert") cfg.servers) - (mapAttrsToList (verifyRequiredField "server" "connect") cfg.servers) + (lib.mapAttrsToList verifyChainPathAssert cfg.clients) + (lib.mapAttrsToList (verifyRequiredField "client" "accept") cfg.clients) + (lib.mapAttrsToList (verifyRequiredField "client" "connect") cfg.clients) + (lib.mapAttrsToList (verifyRequiredField "server" "accept") cfg.servers) + (lib.mapAttrsToList (verifyRequiredField "server" "cert") cfg.servers) + (lib.mapAttrsToList (verifyRequiredField "server" "connect") cfg.servers) ]; environment.systemPackages = [ pkgs.stunnel ]; environment.etc."stunnel.cfg".text = '' - ${ optionalString (cfg.user != null) "setuid = ${cfg.user}" } - ${ optionalString (cfg.group != null) "setgid = ${cfg.group}" } + ${ lib.optionalString (cfg.user != null) "setuid = ${cfg.user}" } + ${ lib.optionalString (cfg.group != null) "setgid = ${cfg.group}" } debug = ${cfg.logLevel} - ${ optionalString cfg.fipsMode "fips = yes" } - ${ optionalString cfg.enableInsecureSSLv3 "options = -NO_SSLv3" } + ${ lib.optionalString cfg.fipsMode "fips = yes" } + ${ lib.optionalString cfg.enableInsecureSSLv3 "options = -NO_SSLv3" } ; ----- SERVER CONFIGURATIONS ----- ${ generateConfig cfg.servers } @@ -181,7 +178,7 @@ in }; }; - meta.maintainers = with maintainers; [ + meta.maintainers = with lib.maintainers; [ # Server side lschuermann # Client side From 1fdd6dfe48f7db2cafec60d36db8f7ce9cf45ddf Mon Sep 17 00:00:00 2001 From: Bruno BELANYI Date: Wed, 27 Nov 2024 17:52:51 +0000 Subject: [PATCH 157/166] firefox-sync-client: init at 1.8.0 --- .../fi/firefox-sync-client/package.nix | 27 +++++++++++++++++++ 1 file changed, 27 insertions(+) create mode 100644 pkgs/by-name/fi/firefox-sync-client/package.nix diff --git a/pkgs/by-name/fi/firefox-sync-client/package.nix b/pkgs/by-name/fi/firefox-sync-client/package.nix new file mode 100644 index 000000000000..a82b8adf701c --- /dev/null +++ b/pkgs/by-name/fi/firefox-sync-client/package.nix @@ -0,0 +1,27 @@ +{ + lib, + buildGoModule, + fetchFromGitHub, +}: + +buildGoModule rec { + pname = "firefox-sync-client"; + version = "1.8.0"; + + src = fetchFromGitHub { + owner = "Mikescher"; + repo = "firefox-sync-client"; + rev = "v${version}"; + hash = "sha256-Ax+v4a8bVuym1bp9dliXX85PXJk2Qlik3ME+adGiL1s="; + }; + + vendorHash = "sha256-MYetPdnnvIBzrYrA+eM9z1P3+P5FumYKH+brvvlwkm4="; + + meta = { + description = "Commandline-utility to list/view/edit/delete entries in a firefox-sync account."; + homepage = "https://github.com/Mikescher/firefox-sync-client"; + license = lib.licenses.asl20; + maintainers = with lib.maintainers; [ ambroisie ]; + mainProgram = "ffsclient"; + }; +} From d2a0baa169f89c522ff6e42f125c2588042f9986 Mon Sep 17 00:00:00 2001 From: Felix Buehler Date: Thu, 28 Nov 2024 22:23:24 +0100 Subject: [PATCH 158/166] sidequest: fix fhsenv version --- pkgs/by-name/si/sidequest/package.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/si/sidequest/package.nix b/pkgs/by-name/si/sidequest/package.nix index ef8e0a20560b..2bf49bad8e31 100644 --- a/pkgs/by-name/si/sidequest/package.nix +++ b/pkgs/by-name/si/sidequest/package.nix @@ -93,7 +93,8 @@ ''; }; in buildFHSEnv { - name = "SideQuest"; + pname = "SideQuest"; + inherit version; passthru = { inherit pname version; From 49c8101b6feb8c1f8d53400d10bf339f940b596d Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Thu, 28 Nov 2024 22:35:05 +0100 Subject: [PATCH 159/166] python312Packages.aiomisc: 17.5.26 -> 17.5.29 Changelog: https://github.com/aiokitchen/aiomisc/blob/master/CHANGELOG.md --- pkgs/development/python-modules/aiomisc/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/aiomisc/default.nix b/pkgs/development/python-modules/aiomisc/default.nix index a9dabfd3ee2a..629cf183e8a2 100644 --- a/pkgs/development/python-modules/aiomisc/default.nix +++ b/pkgs/development/python-modules/aiomisc/default.nix @@ -22,14 +22,14 @@ buildPythonPackage rec { pname = "aiomisc"; - version = "17.5.26"; + version = "17.5.29"; pyproject = true; disabled = pythonOlder "3.8"; src = fetchPypi { inherit pname version; - hash = "sha256-78N8SBzgUB0Lnbj79r3jfhx6ZwlsP9Eq7gTIPkZSPzM="; + hash = "sha256-DjOl4eymyD2n1bbDUI+s3iGiWjT/AhRqmTmiZpufLNU="; }; build-system = [ poetry-core ]; From 69eb494e6862ae3ec8072c0481970874cc9c6677 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Thu, 28 Nov 2024 22:44:39 +0100 Subject: [PATCH 160/166] python312Packages.python-can: 4.4.2 -> 4.5.0 Diff: https://github.com/hardbyte/python-can/compare/refs/tags/v4.4.2...v4.5.0 Changelog: https://github.com/hardbyte/python-can/releases/tag/v4.5.0 --- .../python-modules/python-can/default.nix | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) diff --git a/pkgs/development/python-modules/python-can/default.nix b/pkgs/development/python-modules/python-can/default.nix index d762c5f0ed69..4272950862f3 100644 --- a/pkgs/development/python-modules/python-can/default.nix +++ b/pkgs/development/python-modules/python-can/default.nix @@ -14,6 +14,7 @@ pytestCheckHook, pythonOlder, setuptools, + setuptools-scm, typing-extensions, wrapt, uptime, @@ -21,21 +22,22 @@ buildPythonPackage rec { pname = "python-can"; - version = "4.4.2"; + version = "4.5.0"; pyproject = true; - disabled = pythonOlder "3.7"; + disabled = pythonOlder "3.8"; src = fetchFromGitHub { owner = "hardbyte"; repo = "python-can"; rev = "refs/tags/v${version}"; - hash = "sha256-p3B1LWSygDX0UhIx4XhXv15H7Hwn9UB20jFIPDZnuNs="; + hash = "sha256-XCv2oOkGq8c2gTo+8UcZbuBYXyhhQstWLyddk3db38s="; }; - pythonRelaxDeps = [ "msgpack" ]; - - build-system = [ setuptools ]; + build-system = [ + setuptools + setuptools-scm + ]; dependencies = [ msgpack From 95a92c04299a1831042f9145c2532db6ced6ba1c Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Thu, 28 Nov 2024 22:46:43 +0100 Subject: [PATCH 161/166] python312Packages.spotifyaio: 0.8.8 -> 0.8.10 Diff: https://github.com/joostlek/python-spotify/compare/refs/tags/v0.8.8...v0.8.10 Changelog: https://github.com/joostlek/python-spotify/releases/tag/v0.8.10 --- pkgs/development/python-modules/spotifyaio/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/spotifyaio/default.nix b/pkgs/development/python-modules/spotifyaio/default.nix index a94b02cfbf8c..c61848e4a5b0 100644 --- a/pkgs/development/python-modules/spotifyaio/default.nix +++ b/pkgs/development/python-modules/spotifyaio/default.nix @@ -17,7 +17,7 @@ buildPythonPackage rec { pname = "spotifyaio"; - version = "0.8.8"; + version = "0.8.10"; pyproject = true; disabled = pythonOlder "3.11"; @@ -26,7 +26,7 @@ buildPythonPackage rec { owner = "joostlek"; repo = "python-spotify"; rev = "refs/tags/v${version}"; - hash = "sha256-4u6YVkFeUF8jHrReFLnQGeC5qxfVyL8tuSHR8Ta74Hw="; + hash = "sha256-+DsJAhSY9gkW5wcVPlwiheDmZYT09y/YkU6Z470nKz0="; }; build-system = [ poetry-core ]; From e7387f290c6764680cbb7d20fddf4a488ee0bbb6 Mon Sep 17 00:00:00 2001 From: Anderson Torres Date: Thu, 28 Nov 2024 21:11:36 -0300 Subject: [PATCH 162/166] treewide: remove AndersonTorres from maintainers --- pkgs/applications/video/openshot-qt/default.nix | 2 +- pkgs/by-name/ci/cimg/package.nix | 4 +--- pkgs/by-name/el/elvish/package.nix | 2 +- pkgs/by-name/fl/flam3/package.nix | 2 +- pkgs/by-name/fl/fleng/package.nix | 2 +- pkgs/by-name/fm/fm-go/package.nix | 2 +- pkgs/by-name/gr/grim/package.nix | 2 +- pkgs/by-name/kc/kconfig-frontends/package.nix | 2 +- pkgs/by-name/ki/kid3/package.nix | 2 +- pkgs/by-name/nv/nv-codec-headers/package.nix | 2 +- pkgs/by-name/re/refind/package.nix | 2 +- pkgs/by-name/re/revup/package.nix | 2 +- pkgs/by-name/sc/scons/package.nix | 2 +- pkgs/by-name/sd/SDL2_mixer/package.nix | 2 +- pkgs/by-name/so/so/package.nix | 1 - pkgs/by-name/so/sov/package.nix | 2 +- pkgs/by-name/wt/wtfis/package.nix | 2 +- pkgs/by-name/xp/xpointerbarrier/package.nix | 1 - pkgs/development/libraries/libopenshot-audio/default.nix | 2 +- pkgs/development/libraries/libopenshot/default.nix | 2 +- pkgs/development/python-modules/yapf/default.nix | 1 - pkgs/top-level/perl-packages.nix | 2 +- 22 files changed, 19 insertions(+), 24 deletions(-) diff --git a/pkgs/applications/video/openshot-qt/default.nix b/pkgs/applications/video/openshot-qt/default.nix index ec6e309e9b82..1f1da89340c7 100644 --- a/pkgs/applications/video/openshot-qt/default.nix +++ b/pkgs/applications/video/openshot-qt/default.nix @@ -90,7 +90,7 @@ mkDerivationWith python3.pkgs.buildPythonApplication { ''; license = with lib.licenses; [ gpl3Plus ]; mainProgram = "openshot-qt"; - maintainers = with lib.maintainers; [ AndersonTorres ]; + maintainers = with lib.maintainers; [ ]; platforms = lib.platforms.unix; }; } diff --git a/pkgs/by-name/ci/cimg/package.nix b/pkgs/by-name/ci/cimg/package.nix index 6b55ca755120..a5112b210720 100644 --- a/pkgs/by-name/ci/cimg/package.nix +++ b/pkgs/by-name/ci/cimg/package.nix @@ -45,9 +45,7 @@ stdenv.mkDerivation (finalAttrs: { processing applications. ''; license = lib.licenses.cecill-c; - maintainers = [ - lib.maintainers.AndersonTorres - ]; + maintainers = [ ]; platforms = lib.platforms.unix; }; }) diff --git a/pkgs/by-name/el/elvish/package.nix b/pkgs/by-name/el/elvish/package.nix index 77e8b949b4b4..36d2214a2a13 100644 --- a/pkgs/by-name/el/elvish/package.nix +++ b/pkgs/by-name/el/elvish/package.nix @@ -49,6 +49,6 @@ buildGoModule { status, it is already suitable for most daily interactive use. ''; license = lib.licenses.bsd2; - maintainers = with lib.maintainers; [ AndersonTorres ]; + maintainers = with lib.maintainers; [ ]; }; } diff --git a/pkgs/by-name/fl/flam3/package.nix b/pkgs/by-name/fl/flam3/package.nix index 4eb0bc67c3f0..121485b081e8 100644 --- a/pkgs/by-name/fl/flam3/package.nix +++ b/pkgs/by-name/fl/flam3/package.nix @@ -36,7 +36,7 @@ stdenv.mkDerivation rec { is specified by a long string of numbers - a genetic code of sorts. ''; license = licenses.gpl3Plus; - maintainers = with maintainers; [ AndersonTorres ]; + maintainers = with maintainers; [ ]; platforms = platforms.unix; }; } diff --git a/pkgs/by-name/fl/fleng/package.nix b/pkgs/by-name/fl/fleng/package.nix index 0c2c8359f65a..38cb24d4ea7c 100644 --- a/pkgs/by-name/fl/fleng/package.nix +++ b/pkgs/by-name/fl/fleng/package.nix @@ -18,7 +18,7 @@ stdenv.mkDerivation (finalAttrs: { homepage = "http://www.call-with-current-continuation.org/fleng/fleng.html"; description = "Low level concurrent logic programming language descended from Prolog"; license = lib.licenses.publicDomain; - maintainers = with lib.maintainers; [ AndersonTorres ]; + maintainers = with lib.maintainers; [ ]; platforms = lib.platforms.unix; }; }) diff --git a/pkgs/by-name/fm/fm-go/package.nix b/pkgs/by-name/fm/fm-go/package.nix index e0bda5a43b17..27c4867426fb 100644 --- a/pkgs/by-name/fm/fm-go/package.nix +++ b/pkgs/by-name/fm/fm-go/package.nix @@ -23,7 +23,7 @@ let changelog = "https://github.com/mistakenelf/fm/releases/tag/${finalAttrs.src.rev}"; license = with lib.licenses; [ mit ]; mainProgram = "fm"; - maintainers = with lib.maintainers; [ AndersonTorres ]; + maintainers = with lib.maintainers; [ ]; }; }; in diff --git a/pkgs/by-name/gr/grim/package.nix b/pkgs/by-name/gr/grim/package.nix index 72abbb46c7b0..c728f5f19aa2 100644 --- a/pkgs/by-name/gr/grim/package.nix +++ b/pkgs/by-name/gr/grim/package.nix @@ -50,7 +50,7 @@ stdenv.mkDerivation (finalAttrs: { description = "Grab images from a Wayland compositor"; license = lib.licenses.mit; mainProgram = "grim"; - maintainers = with lib.maintainers; [ AndersonTorres ]; + maintainers = with lib.maintainers; [ ]; platforms = lib.platforms.linux; }; }) diff --git a/pkgs/by-name/kc/kconfig-frontends/package.nix b/pkgs/by-name/kc/kconfig-frontends/package.nix index 954ca475a75d..b2c74e330f87 100644 --- a/pkgs/by-name/kc/kconfig-frontends/package.nix +++ b/pkgs/by-name/kc/kconfig-frontends/package.nix @@ -60,7 +60,7 @@ stdenv.mkDerivation (finalAttrs: { ''; homepage = "https://bitbucket.org/nuttx/tools/"; license = lib.licenses.gpl2Plus; - maintainers = with lib.maintainers; [ AndersonTorres ]; + maintainers = with lib.maintainers; [ ]; platforms = lib.platforms.unix; }; }) diff --git a/pkgs/by-name/ki/kid3/package.nix b/pkgs/by-name/ki/kid3/package.nix index 7f314d6bb2e3..ca7416a60167 100644 --- a/pkgs/by-name/ki/kid3/package.nix +++ b/pkgs/by-name/ki/kid3/package.nix @@ -136,7 +136,7 @@ stdenv.mkDerivation (finalAttrs: { "kid3" else "kid3-cli"; - maintainers = with lib.maintainers; [ AndersonTorres ]; + maintainers = with lib.maintainers; [ ]; platforms = lib.platforms.linux; }; }) diff --git a/pkgs/by-name/nv/nv-codec-headers/package.nix b/pkgs/by-name/nv/nv-codec-headers/package.nix index c1183935b91c..39179db9034f 100644 --- a/pkgs/by-name/nv/nv-codec-headers/package.nix +++ b/pkgs/by-name/nv/nv-codec-headers/package.nix @@ -32,7 +32,7 @@ stdenvNoCC.mkDerivation { homepage = "https://ffmpeg.org/"; downloadPage = "https://git.videolan.org/?p=ffmpeg/nv-codec-headers.git"; license = with lib.licenses; [ mit ]; - maintainers = with lib.maintainers; [ AndersonTorres ]; + maintainers = with lib.maintainers; [ ]; platforms = lib.platforms.all; }; } diff --git a/pkgs/by-name/re/refind/package.nix b/pkgs/by-name/re/refind/package.nix index 2958d3be85fd..0b011096fdf1 100644 --- a/pkgs/by-name/re/refind/package.nix +++ b/pkgs/by-name/re/refind/package.nix @@ -146,7 +146,7 @@ stdenv.mkDerivation rec { Linux kernels that provide EFI stub support. ''; homepage = "http://refind.sourceforge.net/"; - maintainers = with maintainers; [ AndersonTorres chewblacka ]; + maintainers = with maintainers; [ chewblacka ]; platforms = [ "i686-linux" "x86_64-linux" "aarch64-linux" ]; license = licenses.gpl3Plus; }; diff --git a/pkgs/by-name/re/revup/package.nix b/pkgs/by-name/re/revup/package.nix index 4fb1e309b201..fe47f2c58437 100644 --- a/pkgs/by-name/re/revup/package.nix +++ b/pkgs/by-name/re/revup/package.nix @@ -70,7 +70,7 @@ let ''; license = lib.licenses.mit; mainProgram = "revup"; - maintainers = with lib.maintainers; [ AndersonTorres ]; + maintainers = with lib.maintainers; [ ]; }; }; in diff --git a/pkgs/by-name/sc/scons/package.nix b/pkgs/by-name/sc/scons/package.nix index f2b6790d1aad..06d97f81b185 100644 --- a/pkgs/by-name/sc/scons/package.nix +++ b/pkgs/by-name/sc/scons/package.nix @@ -45,6 +45,6 @@ python3Packages.buildPythonApplication rec { ''; homepage = "https://scons.org/"; license = lib.licenses.mit; - maintainers = with lib.maintainers; [ AndersonTorres ]; + maintainers = with lib.maintainers; [ ]; }; } diff --git a/pkgs/by-name/sd/SDL2_mixer/package.nix b/pkgs/by-name/sd/SDL2_mixer/package.nix index bd2894f5583d..27f9bc993371 100644 --- a/pkgs/by-name/sd/SDL2_mixer/package.nix +++ b/pkgs/by-name/sd/SDL2_mixer/package.nix @@ -80,7 +80,7 @@ stdenv.mkDerivation (finalAttrs: { description = "SDL multi-channel audio mixer library"; license = lib.licenses.zlib; maintainers = lib.teams.sdl.members - ++ (with lib.maintainers; [ AndersonTorres ]); + ++ (with lib.maintainers; [ ]); platforms = lib.platforms.unix; }; }) diff --git a/pkgs/by-name/so/so/package.nix b/pkgs/by-name/so/so/package.nix index 12c978a9b3aa..a5493b3c76b3 100644 --- a/pkgs/by-name/so/so/package.nix +++ b/pkgs/by-name/so/so/package.nix @@ -59,7 +59,6 @@ let mainProgram = "so"; license = lib.licenses.mit; maintainers = with lib.maintainers; [ - AndersonTorres unsolvedcypher ]; }; diff --git a/pkgs/by-name/so/sov/package.nix b/pkgs/by-name/so/sov/package.nix index e01b1c8f9446..747c39e7cadb 100644 --- a/pkgs/by-name/so/sov/package.nix +++ b/pkgs/by-name/so/sov/package.nix @@ -61,7 +61,7 @@ stdenv.mkDerivation (finalAttrs: { description = "Workspace overview app for sway"; license = lib.licenses.gpl3Only; mainProgram = "sov"; - maintainers = with lib.maintainers; [ AndersonTorres ]; + maintainers = with lib.maintainers; [ ]; inherit (wayland.meta) platforms; # sys/timerfd.h header inexistent broken = stdenv.isDarwin; diff --git a/pkgs/by-name/wt/wtfis/package.nix b/pkgs/by-name/wt/wtfis/package.nix index a4ab234b1b53..80e500ba726e 100644 --- a/pkgs/by-name/wt/wtfis/package.nix +++ b/pkgs/by-name/wt/wtfis/package.nix @@ -39,6 +39,6 @@ in python3.pkgs.buildPythonApplication { description = "Passive hostname, domain and IP lookup tool for non-robots"; mainProgram = "wtfis"; license = lib.licenses.mit; - maintainers = [ lib.maintainers.AndersonTorres ]; + maintainers = [ ]; }; } diff --git a/pkgs/by-name/xp/xpointerbarrier/package.nix b/pkgs/by-name/xp/xpointerbarrier/package.nix index 06dc1c64b790..425018ceb1b1 100644 --- a/pkgs/by-name/xp/xpointerbarrier/package.nix +++ b/pkgs/by-name/xp/xpointerbarrier/package.nix @@ -38,7 +38,6 @@ stdenv.mkDerivation (finalAttrs: { description = "Create X11 pointer barriers around your working area"; license = licenses.mit; maintainers = with maintainers; [ - AndersonTorres xzfc ]; platforms = platforms.linux; diff --git a/pkgs/development/libraries/libopenshot-audio/default.nix b/pkgs/development/libraries/libopenshot-audio/default.nix index 2d8cec21b189..9dfa5e09eddb 100644 --- a/pkgs/development/libraries/libopenshot-audio/default.nix +++ b/pkgs/development/libraries/libopenshot-audio/default.nix @@ -71,7 +71,7 @@ stdenv.mkDerivation (finalAttrs: { JUCE library. ''; license = with lib.licenses; [ gpl3Plus ]; - maintainers = with lib.maintainers; [ AndersonTorres ]; + maintainers = with lib.maintainers; [ ]; platforms = lib.platforms.unix; }; }) diff --git a/pkgs/development/libraries/libopenshot/default.nix b/pkgs/development/libraries/libopenshot/default.nix index 231b0cd109aa..564ad3ac911a 100644 --- a/pkgs/development/libraries/libopenshot/default.nix +++ b/pkgs/development/libraries/libopenshot/default.nix @@ -81,7 +81,7 @@ stdenv.mkDerivation (finalAttrs: { to the world. API currently supports C++, Python, and Ruby. ''; license = with lib.licenses; [ gpl3Plus ]; - maintainers = with lib.maintainers; [ AndersonTorres ]; + maintainers = with lib.maintainers; [ ]; platforms = lib.platforms.unix; }; }) diff --git a/pkgs/development/python-modules/yapf/default.nix b/pkgs/development/python-modules/yapf/default.nix index 38e62c57eef8..dfe624106627 100644 --- a/pkgs/development/python-modules/yapf/default.nix +++ b/pkgs/development/python-modules/yapf/default.nix @@ -59,7 +59,6 @@ buildPythonPackage rec { license = lib.licenses.asl20; mainProgram = "yapf"; maintainers = with lib.maintainers; [ - AndersonTorres siddharthist ]; }; diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index f339c7c80c24..6c243b3879b3 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -5975,7 +5975,7 @@ with self; { description = "Hexadecial Dumper"; homepage = "https://github.com/neilb/Data-HexDump"; license = with lib.licenses; [ artistic1 gpl1Plus ]; - maintainers = with maintainers; [ AndersonTorres ]; + maintainers = with maintainers; [ ]; mainProgram = "hexdump"; }; }; From be84d0bc4475db15283b626db197c8fa48160166 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 29 Nov 2024 09:36:13 +0000 Subject: [PATCH 163/166] mongoc: 1.28.0 -> 1.29.0 --- pkgs/development/libraries/mongoc/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/mongoc/default.nix b/pkgs/development/libraries/mongoc/default.nix index fc967445d01c..577ca980cbf2 100644 --- a/pkgs/development/libraries/mongoc/default.nix +++ b/pkgs/development/libraries/mongoc/default.nix @@ -14,13 +14,13 @@ stdenv.mkDerivation rec { pname = "mongoc"; - version = "1.28.0"; + version = "1.29.0"; src = fetchFromGitHub { owner = "mongodb"; repo = "mongo-c-driver"; rev = "refs/tags/${version}"; - hash = "sha256-cfet+A2i33iHbVRouPS4Ul8TmHolrcIMTRba6Olqfeg="; + hash = "sha256-367qk0u81jnNA/9ruCo9wUWnCPrNjLhp9x62iEpCmE4="; }; nativeBuildInputs = [ From f3d53e22f75cf7219d5ef75eb7b2fc5bcfcd4649 Mon Sep 17 00:00:00 2001 From: bloominstrong Date: Wed, 9 Oct 2024 21:36:46 +1000 Subject: [PATCH 164/166] mupen64plus: 2.5.9 -> 2.6.0 https://github.com/mupen64plus/mupen64plus-core/blob/2.6.0/RELEASE --- pkgs/by-name/mu/mupen64plus/package.nix | 50 ++++++++++++++++--------- 1 file changed, 33 insertions(+), 17 deletions(-) diff --git a/pkgs/by-name/mu/mupen64plus/package.nix b/pkgs/by-name/mu/mupen64plus/package.nix index 81c86eeafecb..5206d4abc37d 100644 --- a/pkgs/by-name/mu/mupen64plus/package.nix +++ b/pkgs/by-name/mu/mupen64plus/package.nix @@ -1,29 +1,45 @@ -{lib, stdenv, fetchurl, fetchpatch, boost, dash, freetype, libpng, pkg-config, SDL, which, zlib, nasm }: +{ + lib, + stdenv, + fetchurl, + fetchpatch, + boost, + dash, + freetype, + libpng, + libGLU, + pkg-config, + SDL2, + which, + zlib, + nasm, + vulkan-loader, +}: stdenv.mkDerivation rec { pname = "mupen64plus"; - version = "2.5.9"; + version = "2.6.0"; src = fetchurl { url = "https://github.com/mupen64plus/mupen64plus-core/releases/download/${version}/mupen64plus-bundle-src-${version}.tar.gz"; - sha256 = "1a21n4gqdvag6krwcjm5bnyw5phrlxw6m0mk73jy53iq03f3s96m"; + sha256 = "sha256-KX4XGAzXanuOqAnRob4smO1cc1LccWllqA3rWYsh4TE="; }; - patches = [ - # Pull upstream fix for -fno-common toolchains: - # https://github.com/mupen64plus/mupen64plus-core/pull/736 - (fetchpatch { - name = "fno-common.patch"; - url = "https://github.com/mupen64plus/mupen64plus-core/commit/39975200ad4926cfc79c96609b64696289065502.patch"; - sha256 = "0kdshp9xdkharn3d1g1pvxhh761pa1v5w07iq0wf9l380r2m6gbv"; - # a/something -> a/source/mupen64plus-core/something - stripLen = 1; - extraPrefix = "source/mupen64plus-core/"; - }) + nativeBuildInputs = [ + pkg-config + nasm + ]; + buildInputs = [ + boost + dash + freetype + libpng + libGLU + SDL2 + which + zlib + vulkan-loader ]; - - nativeBuildInputs = [ pkg-config nasm ]; - buildInputs = [ boost dash freetype libpng SDL which zlib ]; buildPhase = '' dash m64p_build.sh PREFIX="$out" COREDIR="$out/lib/" PLUGINDIR="$out/lib/mupen64plus" SHAREDIR="$out/share/mupen64plus" From ea0adc05b506daf5986908fde1859eda9d84bbfe Mon Sep 17 00:00:00 2001 From: misilelaboratory Date: Fri, 29 Nov 2024 23:58:46 +0900 Subject: [PATCH 165/166] pnpm: 9.14.2 -> 9.14.4 Signed-off-by: misilelaboratory --- pkgs/development/tools/pnpm/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/tools/pnpm/default.nix b/pkgs/development/tools/pnpm/default.nix index 36b5e8d7a5e2..860fcb1cc0a4 100644 --- a/pkgs/development/tools/pnpm/default.nix +++ b/pkgs/development/tools/pnpm/default.nix @@ -12,8 +12,8 @@ let hash = "sha256-2qJ6C1QbxjUyP/lsLe2ZVGf/n+bWn/ZwIVWKqa2dzDY="; }; "9" = { - version = "9.14.2"; - hash = "sha256-BuZaSWW6/21gl/nI91w19tQgl028A9d1AJBWpp7f0nE="; + version = "9.14.4"; + hash = "sha256-JqcmtjO2KaP6vaAG9pauQmCVSjYyyAVBEteuiXeeX5o="; }; }; From 47da8867f3cf1cd2200cbc0c38148e7265e51d84 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 29 Nov 2024 20:39:59 +0000 Subject: [PATCH 166/166] python312Packages.kafka-python-ng: 2.2.2 -> 2.2.3 --- pkgs/development/python-modules/kafka-python-ng/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/kafka-python-ng/default.nix b/pkgs/development/python-modules/kafka-python-ng/default.nix index 79d253cacc8e..6252e1a5044a 100644 --- a/pkgs/development/python-modules/kafka-python-ng/default.nix +++ b/pkgs/development/python-modules/kafka-python-ng/default.nix @@ -15,7 +15,7 @@ }: buildPythonPackage rec { - version = "2.2.2"; + version = "2.2.3"; pname = "kafka-python-ng"; pyproject = true; @@ -25,7 +25,7 @@ buildPythonPackage rec { owner = "wbarnha"; repo = "kafka-python-ng"; rev = "refs/tags/v${version}"; - hash = "sha256-ELJvcj91MQ2RTjT1dwgnTGSSG5lP6B6/45dFgtNY2Cc="; + hash = "sha256-a2RFiBRh3S2YQBekpwEK74ow8bGlgWCGqSf2vcgYPYk="; }; build-system = [ setuptools-scm ];