From 4dcde98327cf1d54cdcdd8aa2736b09f6fc348e8 Mon Sep 17 00:00:00 2001 From: Will Fancher Date: Sun, 16 Mar 2025 22:01:47 -0400 Subject: [PATCH] nixos/sshd: Fix socket activated SSH connections entering failed state. In afeb76d6287955bc8c638365ebefe71a1fd7302a, sshd.service and sshd@.service were switched to Type=notify. This apparently works for sshd.service, but not for sshd@.service. Given that the reason for this working with sshd.service isn't exactly clear, let's revert it for both of them for now, and revisit Type=notify later. --- nixos/modules/services/networking/ssh/sshd.nix | 2 -- nixos/tests/openssh.nix | 3 +++ 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/nixos/modules/services/networking/ssh/sshd.nix b/nixos/modules/services/networking/ssh/sshd.nix index 42014f52aab8..5fa3651e0ccb 100644 --- a/nixos/modules/services/networking/ssh/sshd.nix +++ b/nixos/modules/services/networking/ssh/sshd.nix @@ -593,7 +593,6 @@ in environment.LD_LIBRARY_PATH = nssModulesPath; serviceConfig = { - Type = "notify"; ExecStart = lib.concatStringsSep " " [ "-${lib.getExe' cfg.package "sshd"}" "-i" @@ -618,7 +617,6 @@ in restartTriggers = [ config.environment.etc."ssh/sshd_config".source ]; serviceConfig = { - Type = "notify"; Restart = "always"; ExecStart = lib.concatStringsSep " " [ (lib.getExe' cfg.package "sshd") diff --git a/nixos/tests/openssh.nix b/nixos/tests/openssh.nix index 92829001f2dd..7d53aaf9c4d5 100644 --- a/nixos/tests/openssh.nix +++ b/nixos/tests/openssh.nix @@ -274,5 +274,8 @@ in { "ssh -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no -i privkey.snakeoil server-no-pam true", timeout=30 ) + + # None of the per-connection units should have failed. + server_lazy.fail("systemctl is-failed 'sshd@*.service'") ''; })