diff --git a/nixos/doc/manual/administration/boot-problems.section.md b/nixos/doc/manual/administration/boot-problems.section.md index bca4fdc3fb38..357c6e5ea0ef 100644 --- a/nixos/doc/manual/administration/boot-problems.section.md +++ b/nixos/doc/manual/administration/boot-problems.section.md @@ -1,41 +1,61 @@ # Boot Problems {#sec-boot-problems} -If NixOS fails to boot, there are a number of kernel command line parameters that may help you to identify or fix the issue. You can add these parameters in the GRUB boot menu by pressing “e” to modify the selected boot entry and editing the line starting with `linux`. The following are some useful kernel command line parameters that are recognised by the NixOS boot scripts or by systemd: +If NixOS fails to boot, there are a number of kernel command line parameters that may help you to identify or fix the issue. You can add these parameters in the GRUB boot menu by pressing “e” to modify the selected boot entry and editing the line starting with `linux`. -`boot.shell_on_fail` - -: Allows the user to start a root shell if something goes wrong in stage 1 of the boot process (the initial ramdisk). This is disabled by default because there is no authentication for the root shell. - -`boot.debug1` - -: Start an interactive shell in stage 1 before anything useful has been done. That is, no modules have been loaded and no file systems have been mounted, except for `/proc` and `/sys`. - -`boot.debug1devices` - -: Like `boot.debug1`, but runs stage1 until kernel modules are loaded and device nodes are created. This may help with e.g. making the keyboard work. - -`boot.debug1mounts` - -: Like `boot.debug1` or `boot.debug1devices`, but runs stage1 until all filesystems that are mounted during initrd are mounted (see [neededForBoot](#opt-fileSystems._name_.neededForBoot)). As a motivating example, this could be useful if you've forgotten to set [neededForBoot](#opt-fileSystems._name_.neededForBoot) on a file system. - -`boot.trace` - -: Print every shell command executed by the stage 1 and 2 boot scripts. - -`single` - -: Boot into rescue mode (a.k.a. single user mode). This will cause systemd to start nothing but the unit `rescue.target`, which runs `sulogin` to prompt for the root password and start a root login shell. Exiting the shell causes the system to continue with the normal boot process. - -`systemd.log_level=debug` `systemd.log_target=console` - -: Make systemd very verbose and send log messages to the console instead of the journal. For more parameters recognised by systemd, see systemd(1). - -In addition, these arguments are recognised by the live image only: +{manpage}`kernel-command-line(7)` documents the kernel parameters accepted by systemd. Those include many that are helpful for debugging boot issues, such as `systemd.debug_shell` and `rescue`. Some also have `rd.`‐prefixed variants that apply to stage 1. `live.nixos.passwd=password` : Set the password for the `nixos` live user. This can be used for SSH access if there are issues using the terminal. -Notice that for `boot.shell_on_fail`, `boot.debug1`, `boot.debug1devices`, and `boot.debug1mounts`, if you did **not** select "start the new shell as pid 1", and you `exit` from the new shell, boot will proceed normally from the point where it failed, as if you'd chosen "ignore the error and continue". +If no login prompts or X11 login screens appear (e.g. due to hanging dependencies), you can press Alt+ArrowUp. If you’re lucky, this will start `rescue.target` (described in {manpage}`systemd.special(7)`). (Also note that since most units have a 90-second timeout before systemd gives up on them, the `agetty` login prompts should appear eventually unless something is very wrong.) -If no login prompts or X11 login screens appear (e.g. due to hanging dependencies), you can press Alt+ArrowUp. If you’re lucky, this will start rescue mode (described above). (Also note that since most units have a 90-second timeout before systemd gives up on them, the `agetty` login prompts should appear eventually unless something is very wrong.) +## Scripted stage 1 {#sec-boot-problems-scripted-stage-1} + +The scripted implementation of stage 1 also understands these boot parameters. + +::: {.warning} +The scripted implementation of stage 1 is disabled by default and deprecated. These parameters have no effect, unless systemd stage 1 is explicitly disabled with `boot.initrd.systemd.enable = false;`. +::: + +`boot.shell_on_fail` + +: Allows the user to start a root shell if something goes wrong in stage 1 of the boot process (the initial ramdisk). This is disabled by default because there is no authentication for the root shell. + + ::: {.note} + systemd stage 1 alternative: `SYSTEMD_SULOGIN_FORCE=1` for rescue mode, or `rd.systemd.debug_shell` for shell on tty9. + ::: + +`boot.debug1` + +: Start an interactive shell in stage 1 before anything useful has been done. That is, no modules have been loaded and no file systems have been mounted, except for `/proc` and `/sys`. + + ::: {.note} + systemd stage 1 alternative: `rd.systemd.break=pre-udev` + ::: + +`boot.debug1devices` + +: Like `boot.debug1`, but runs stage1 until kernel modules are loaded and device nodes are created. This may help with e.g. making the keyboard work. + + ::: {.note} + systemd stage 1 alternative: `rd.systemd.break=pre-mount` + ::: + +`boot.debug1mounts` + +: Like `boot.debug1` or `boot.debug1devices`, but runs stage1 until all filesystems that are mounted during initrd are mounted (see [neededForBoot](#opt-fileSystems._name_.neededForBoot)). As a motivating example, this could be useful if you've forgotten to set [neededForBoot](#opt-fileSystems._name_.neededForBoot) on a file system. + + ::: {.note} + systemd stage 1 alternative: `rd.systemd.break=pre-switch-root` + ::: + +`boot.trace` + +: Print every shell command executed by the stage 1 and 2 boot scripts. + + ::: {.note} + systemd stage 1 alternative: `rd.systemd.log_level=debug` + ::: + +Notice that for `boot.shell_on_fail`, `boot.debug1`, `boot.debug1devices`, and `boot.debug1mounts`, if you did **not** select "start the new shell as pid 1", and you `exit` from the new shell, boot will proceed normally from the point where it failed, as if you'd chosen "ignore the error and continue". diff --git a/nixos/doc/manual/installation/installing-from-other-distro.section.md b/nixos/doc/manual/installation/installing-from-other-distro.section.md index 56b1cca00e05..2b9d3171264a 100644 --- a/nixos/doc/manual/installation/installing-from-other-distro.section.md +++ b/nixos/doc/manual/installation/installing-from-other-distro.section.md @@ -149,6 +149,10 @@ The first steps to all these are the same: `NIXOS_LUSTRATE`: ::: + ::: {.warning} + The lustrate process will not work if the [](#opt-boot.initrd.systemd.enable) option is set to `true`, which is now the default. Setting this to `false` is deprecated and scheduled for removal in NixOS 26.11, along with `NIXOS_LUSTRATE`. Other installation methods, such as the one outlined above, or installing from [kexec](#sec-booting-via-kexec), are recommended instead. + ::: + Generate your NixOS configuration: ```ShellSession @@ -167,11 +171,6 @@ The first steps to all these are the same: If the current system and NixOS's bootloader configuration don't agree on where the [EFI System Partition](https://en.wikipedia.org/wiki/EFI_system_partition) is to be mounted, you'll need to manually alter the mount point in `hardware-configuration.nix` before building the system closure. ::: - ::: {.note} - The lustrate process will not work if the [](#opt-boot.initrd.systemd.enable) option is set to `true`. - If you want to use this option, wait until after the first boot into the NixOS system to enable it and rebuild. - ::: - You'll likely want to set a root password for your first boot using the configuration files because you won't have a chance to enter a password until after you reboot. You can initialize the root password diff --git a/nixos/doc/manual/redirects.json b/nixos/doc/manual/redirects.json index 7bf88472148e..feb535c2142c 100644 --- a/nixos/doc/manual/redirects.json +++ b/nixos/doc/manual/redirects.json @@ -151,6 +151,9 @@ "module-virtualisation-xen-introduction": [ "index.html#module-virtualisation-xen-introduction" ], + "sec-boot-problems-scripted-stage-1": [ + "index.html#sec-boot-problems-scripted-stage-1" + ], "sec-nixos-test-vms-vs-containers": [ "index.html#sec-nixos-test-vms-vs-containers" ], diff --git a/nixos/doc/manual/release-notes/rl-2605.section.md b/nixos/doc/manual/release-notes/rl-2605.section.md index 576f3c6db4c4..d1c68cc8f7aa 100644 --- a/nixos/doc/manual/release-notes/rl-2605.section.md +++ b/nixos/doc/manual/release-notes/rl-2605.section.md @@ -4,6 +4,16 @@ +- Stage 1 (a.k.a. initrd) is now based on systemd by default, and the old scripted implementation is deprecated and scheduled for removal in 26.11. If you run into issues migrating, you can [get help from the community](https://nixos.org/community/) or report an issue on GitHub. + + You can temporarily revert to the scripted stage 1 implementation by disabling [](#opt-boot.initrd.systemd.enable), but this is discouraged. + + Most incompatibilities will be explained with assertions during configuration evaluation, but be aware of the following that can't be automatically detected: + + - If you use LUKS disk encryption, ensure that `fileSystems."/".device` is set to `"/dev/mapper/"`, where `` matches the name in your `boot.initrd.luks.devices.` definition, to avoid systemd timing out while prompting for a passphrase. If you have a more complex setup, e.g. with LVM on top of LUKS, you may need to add `"x-systemd.device-timeout=infinity"` to `fileSystems."/".options` instead. If you need to disable the timeout before you can boot into the system, pass `systemd.default_device_timeout_sec=infinity` on the kernel command line. + - The `cryptsetup-askpass` program is not available; use `systemctl default` instead, which will prompt for passphrases as necessary. If you pipe password responses into SSH over stdin, use `ssh -o RequestTTY=force` to ensure `systemctl default` gets a TTY to prompt on. + - Many kernel parameters have been replaced with native systemd versions; see [](#sec-boot-problems). + - The system.nix file has been added has an alternative entry point to configuration.nix (and flake.nix) that allows to configure NixOS without using `nix-channel`. This file must evaluate to a NixOS system derivation or an attribute set of such derivations, in which case the attribute to build has to be selected with the `--attr` option of `nixos-rebuild` or `nixos-install`. For example, diff --git a/nixos/modules/config/users-groups.nix b/nixos/modules/config/users-groups.nix index 461c219ee807..56ff03aefec1 100644 --- a/nixos/modules/config/users-groups.nix +++ b/nixos/modules/config/users-groups.nix @@ -1143,6 +1143,16 @@ in ''; } ] + ++ flip mapAttrsToList config.boot.initrd.systemd.users ( + name: user: { + assertion = config.boot.initrd.systemd.enable -> (baseNameOf user.shell != "cryptsetup-askpass"); + message = '' + cryptsetup-askpass is not available in systemd stage 1. Please remove it from: boot.initrd.systemd.users.${name}.shell + + Use `systemctl default` instead; see the NixOS 26.05 release notes for details. If you want to continue restricting the command for SSH login, you can use `command="systemctl default"` in SSH authorized keys instead; see `sshd(8)`. + ''; + } + ) ++ flatten ( flip mapAttrsToList cfg.users ( name: user: diff --git a/nixos/modules/services/hardware/nvidia-container-toolkit/default.nix b/nixos/modules/services/hardware/nvidia-container-toolkit/default.nix index 475a5122fd4e..1a1365c5d420 100644 --- a/nixos/modules/services/hardware/nvidia-container-toolkit/default.nix +++ b/nixos/modules/services/hardware/nvidia-container-toolkit/default.nix @@ -320,7 +320,6 @@ systemd.services.nvidia-container-toolkit-cdi-generator = { description = "Container Device Interface (CDI) for Nvidia generator"; - after = [ "systemd-udev-settle.service" ]; requiredBy = lib.mkMerge [ (lib.mkIf config.virtualisation.docker.enable [ "docker.service" ]) (lib.mkIf config.virtualisation.podman.enable [ "podman.service" ]) @@ -329,6 +328,11 @@ serviceConfig = { RuntimeDirectory = "cdi"; RemainAfterExit = true; + # We wait for the udev events queue to empty in the *hope* that the + # devices needed here become available. This is terribly broken and + # essentially no better than a random sleep(). See PR #452645 for + # an attempt to fix this issue. + ExecStartPre = "-${lib.getExe' pkgs.systemd "udevadm"} settle --timeout=180"; ExecStart = let script = pkgs.callPackage ./cdi-generate.nix { diff --git a/nixos/modules/services/hardware/udev.nix b/nixos/modules/services/hardware/udev.nix index 6e779df94e77..1299a5115a5f 100644 --- a/nixos/modules/services/hardware/udev.nix +++ b/nixos/modules/services/hardware/udev.nix @@ -455,7 +455,6 @@ in "systemd-udevd-control.socket" "systemd-udevd-kernel.socket" "systemd-udevd.service" - "systemd-udev-settle.service" "systemd-udev-trigger.service" ]; boot.initrd.systemd.storePaths = [ diff --git a/nixos/modules/services/networking/ifstate.nix b/nixos/modules/services/networking/ifstate.nix index 051322fc1ce5..ef44463ba9cf 100644 --- a/nixos/modules/services/networking/ifstate.nix +++ b/nixos/modules/services/networking/ifstate.nix @@ -69,7 +69,6 @@ let # https://github.com/systemd/systemd/blob/main/units/systemd-networkd.service.in commonServiceConfig = { after = [ - "systemd-udev-settle.service" "network-pre.target" "systemd-sysusers.service" "systemd-sysctl.service" @@ -88,6 +87,12 @@ let "network.target" ]; + # We wait for the udev events queue to empty in the *hope* that the + # devices needed here become available. This is terribly broken and + # essentially no better than a random sleep(). + # FIXME: use .device units dependecies instead. + serviceConfig.ExecStartPre = "-${lib.getExe' pkgs.systemd "udevadm"} settle --timeout=180"; + unitConfig = { # Avoid default dependencies like "basic.target", which prevents ifstate from starting before luks is unlocked. DefaultDependencies = "no"; @@ -173,7 +178,7 @@ in etc."ifstate/ifstate.yaml".source = settingsFormat.generate "ifstate.yaml" cfg.settings cfg.package; }; - systemd.services.ifstate = commonServiceConfig // { + systemd.services.ifstate = lib.recursiveUpdate commonServiceConfig { description = "IfState"; wantedBy = [ @@ -263,7 +268,7 @@ in "remote-fs.target" ]; - services.ifstate-initrd = commonServiceConfig // { + services.ifstate-initrd = lib.recursiveUpdate commonServiceConfig { description = "IfState initrd"; wantedBy = [ diff --git a/nixos/modules/services/system/dbus.nix b/nixos/modules/services/system/dbus.nix index 1e21fe20d714..8cb03b08c2f6 100644 --- a/nixos/modules/services/system/dbus.nix +++ b/nixos/modules/services/system/dbus.nix @@ -32,7 +32,19 @@ in options = { boot.initrd.systemd.dbus = { - enable = mkEnableOption "dbus in stage 1"; + enable = mkEnableOption "dbus in stage 1" // { + # TODO: This isn't really necessary, but it avoids a very + # common red herring error message: + # + # $ systemctl ... + # Failed to connect to system scope bus via local transport: No such file or directory. + # + # When systemctl tries and fails to control the system manager + # over dbus, it fals back to a private bus socket after + # printing this message. It works, but users often think it is + # the source of their problem when it isn't. + default = true; + }; }; services.dbus = { @@ -163,6 +175,13 @@ in "${config.boot.initrd.systemd.package}/share/dbus-1/system.d" ]; targets.sockets.wants = [ "dbus.socket" ]; + + # Otherwise, dbus waits on cryptsetup, and systemctl says the + # bus couldn't be found. This isn't an error (systemctl will + # fall back to a private bus with PID 1), but it's confusing + # to unaware users. + services.dbus.unitConfig.DefaultDependencies = false; + sockets.dbus.unitConfig.DefaultDependencies = false; }; }) diff --git a/nixos/modules/system/boot/luksroot.nix b/nixos/modules/system/boot/luksroot.nix index 3f5bd56539a0..9ffc0df58d82 100644 --- a/nixos/modules/system/boot/luksroot.nix +++ b/nixos/modules/system/boot/luksroot.nix @@ -998,7 +998,6 @@ in type = with types; listOf singleLineStr; default = [ ]; example = [ "_netdev" ]; - visible = false; description = '' Only used with systemd stage 1. diff --git a/nixos/modules/system/boot/stage-1.nix b/nixos/modules/system/boot/stage-1.nix index 003ff7c78cff..08ab6bec05a1 100644 --- a/nixos/modules/system/boot/stage-1.nix +++ b/nixos/modules/system/boot/stage-1.nix @@ -727,6 +727,10 @@ in }; config = mkIf config.boot.initrd.enable { + warnings = lib.optional (!config.boot.initrd.systemd.enable) '' + Scripted initrd is deprecated and scheduled for removal in 26.11. See the NixOS 26.05 release notes. + ''; + assertions = [ { assertion = !config.boot.initrd.systemd.enable -> any (fs: fs.mountPoint == "/") fileSystems; diff --git a/nixos/modules/system/boot/systemd.nix b/nixos/modules/system/boot/systemd.nix index 2fdd0e1a017a..8c2735c00b8c 100644 --- a/nixos/modules/system/boot/systemd.nix +++ b/nixos/modules/system/boot/systemd.nix @@ -65,7 +65,6 @@ let "systemd-udevd-control.socket" "systemd-udevd-kernel.socket" "systemd-udevd.service" - "systemd-udev-settle.service" ] ++ (optional (!config.boot.isContainer) "systemd-udev-trigger.service") ++ [ @@ -792,10 +791,13 @@ in path = [ pkgs.util-linux ]; overrideStrategy = "asDropin"; }; + systemd.services."modprobe@" = { + restartIfChanged = false; + serviceConfig.ExecSearchPath = lib.makeBinPath [ pkgs.kmod ]; + }; systemd.services.systemd-random-seed.restartIfChanged = false; systemd.services.systemd-remount-fs.restartIfChanged = false; systemd.services.systemd-update-utmp.restartIfChanged = false; - systemd.services.systemd-udev-settle.restartIfChanged = false; # Causes long delays in nixos-rebuild systemd.targets.local-fs.unitConfig.X-StopOnReconfiguration = true; systemd.targets.remote-fs.unitConfig.X-StopOnReconfiguration = true; systemd.services.systemd-importd.environment = proxy_env; diff --git a/nixos/modules/system/boot/systemd/initrd.nix b/nixos/modules/system/boot/systemd/initrd.nix index 2c59d224176e..c3713c026b0e 100644 --- a/nixos/modules/system/boot/systemd/initrd.nix +++ b/nixos/modules/system/boot/systemd/initrd.nix @@ -29,6 +29,10 @@ let upstreamUnits = [ "basic.target" + "breakpoint-pre-udev.service" + "breakpoint-pre-basic.service" + "breakpoint-pre-mount.service" + "breakpoint-pre-switch-root.service" "ctrl-alt-del.target" "debug-shell.service" "emergency.service" @@ -153,6 +157,7 @@ in options.boot.initrd.systemd = { enable = mkEnableOption "systemd in initrd" // { + default = true; description = '' Whether to enable systemd in initrd. The unit options such as {option}`boot.initrd.systemd.services` are the same as their @@ -423,42 +428,57 @@ in }; config = mkIf (config.boot.initrd.enable && cfg.enable) { - assertions = [ - { - assertion = - cfg.root == "fstab" -> any (fs: fs.mountPoint == "/") (builtins.attrValues config.fileSystems); - message = "The ‘fileSystems’ option does not specify your root file system."; - } - ] - ++ - map - (name: { - assertion = lib.attrByPath name (throw "impossible") config.boot.initrd == ""; - message = '' - systemd stage 1 does not support 'boot.initrd.${lib.concatStringsSep "." name}'. Please - convert it to analogous systemd units in 'boot.initrd.systemd'. - - Definitions: - ${lib.concatMapStringsSep "\n" ({ file, ... }: " - ${file}") - (lib.attrByPath name (throw "impossible") options.boot.initrd).definitionsWithLocations - } - ''; - }) - [ - [ "preFailCommands" ] - [ "preDeviceCommands" ] - [ "preLVMCommands" ] - [ "postDeviceCommands" ] - [ "postResumeCommands" ] - [ "postMountCommands" ] - [ "extraUdevRulesCommands" ] - [ "extraUtilsCommands" ] - [ "extraUtilsCommandsTest" ] + assertions = + let + obsoleteOpt = + opts: msgFn: + lib.flip map opts (opt: { + assertion = lib.attrByPath opt (throw "impossible") config.boot.initrd == ""; + message = '' + ${msgFn (lib.concatStringsSep "." opt)} + Definitions: + ${lib.concatMapStringsSep "\n" ({ file, ... }: " - ${file}") + (lib.attrByPath opt (throw "impossible") options.boot.initrd).definitionsWithLocations + } + ''; + }); + in + [ + { + assertion = + cfg.root == "fstab" -> any (fs: fs.mountPoint == "/") (builtins.attrValues config.fileSystems); + message = "The ‘fileSystems’ option does not specify your root file system."; + } + ] + ++ + obsoleteOpt [ - "network" - "postCommands" + [ "preFailCommands" ] + [ "preDeviceCommands" ] + [ "preLVMCommands" ] + [ "postDeviceCommands" ] + [ "postResumeCommands" ] + [ "postMountCommands" ] + [ + "network" + "postCommands" + ] ] - ]; + (name: '' + systemd stage 1 does not support `boot.initrd.${name}`. Instead, create systemd services using the `boot.initrd.systemd.services` options, which has an API matching the stage 2 `systemd.services` options. Refer to `bootup(7)`, specifically the sections on "Bootup in the Initrd" and "System Manager Bootup", for information about when various units happen, and order services accordingly. + '') + ++ + obsoleteOpt + [ + [ "extraUtilsCommands" ] + [ "extraUtilsCommandsTest" ] + ] + (name: '' + systemd stage 1 does not support `boot.initrd.${name}`. Instead, use `boot.initrd.systemd.initrdBin`, `boot.initrd.systemd.extraBin`, `boot.initrd.systemd.contents`, or `boot.initrd.systemd.storePaths` to add files to the initrd. + '') + ++ obsoleteOpt [ [ "extraUdevRulesCommands" ] ] (name: '' + systemd stage 1 does not support `boot.initrd.${name}`. Instead, use `boot.initrd.services.udev` to configure udev. + ''); system.build = { inherit initialRamdisk; }; diff --git a/nixos/modules/tasks/filesystems/zfs.nix b/nixos/modules/tasks/filesystems/zfs.nix index a4f27ed840a9..9ee7a5ff86dc 100644 --- a/nixos/modules/tasks/filesystems/zfs.nix +++ b/nixos/modules/tasks/filesystems/zfs.nix @@ -158,16 +158,8 @@ let }: lib.nameValuePair "zfs-import-${pool}" { description = "Import ZFS pool \"${pool}\""; - # We wait for systemd-udev-settle to ensure devices are available, - # but don't *require* it, because mounts shouldn't be killed if it's stopped. - # In the future, hopefully someone will complete this: - # https://github.com/zfsonlinux/zfs/pull/4943 - wants = [ - "systemd-udev-settle.service" - ] - ++ lib.optional (config.boot.initrd.clevis.useTang) "network-online.target"; + wants = lib.optional (config.boot.initrd.clevis.useTang) "network-online.target"; after = [ - "systemd-udev-settle.service" "systemd-modules-load.service" "systemd-ask-password-console.service" ] diff --git a/nixos/modules/virtualisation/openvswitch.nix b/nixos/modules/virtualisation/openvswitch.nix index 5a231fb5888c..4e75d1677955 100644 --- a/nixos/modules/virtualisation/openvswitch.nix +++ b/nixos/modules/virtualisation/openvswitch.nix @@ -67,7 +67,6 @@ in systemd.services.ovsdb = { description = "Open_vSwitch Database Server"; wantedBy = [ "multi-user.target" ]; - after = [ "systemd-udev-settle.service" ]; path = [ cfg.package ]; restartTriggers = [ db diff --git a/nixos/release-combined.nix b/nixos/release-combined.nix index d299ead82a1b..40eb4a0d34ae 100644 --- a/nixos/release-combined.nix +++ b/nixos/release-combined.nix @@ -103,6 +103,24 @@ rec { (onFullSupported "nixos.tests.gnome") (onSystems [ "x86_64-linux" ] "nixos.tests.hibernate") (onFullSupported "nixos.tests.i3wm") + (onSystems [ "aarch64-linux" ] "nixos.tests.installer-systemd-stage-1.simpleUefiSystemdBoot") + (onSystems [ "x86_64-linux" ] "nixos.tests.installer-systemd-stage-1.btrfsSimple") + (onSystems [ "x86_64-linux" ] "nixos.tests.installer-systemd-stage-1.btrfsSubvolDefault") + (onSystems [ "x86_64-linux" ] "nixos.tests.installer-systemd-stage-1.btrfsSubvolEscape") + (onSystems [ "x86_64-linux" ] "nixos.tests.installer-systemd-stage-1.btrfsSubvols") + (onSystems [ "x86_64-linux" ] "nixos.tests.installer-systemd-stage-1.luksroot") + (onSystems [ "x86_64-linux" ] "nixos.tests.installer-systemd-stage-1.lvm") + (onSystems [ "x86_64-linux" ] "nixos.tests.installer-systemd-stage-1.separateBootZfs") + (onSystems [ "x86_64-linux" ] "nixos.tests.installer-systemd-stage-1.separateBootFat") + (onSystems [ "x86_64-linux" ] "nixos.tests.installer-systemd-stage-1.separateBoot") + (onSystems [ "x86_64-linux" ] "nixos.tests.installer-systemd-stage-1.simpleLabels") + (onSystems [ "x86_64-linux" ] "nixos.tests.installer-systemd-stage-1.simpleProvided") + (onSystems [ "x86_64-linux" ] "nixos.tests.installer-systemd-stage-1.simpleUefiSystemdBoot") + (onSystems [ "x86_64-linux" ] "nixos.tests.installer-systemd-stage-1.simple") + (onSystems [ "x86_64-linux" ] "nixos.tests.installer-systemd-stage-1.swraid") + (onSystems [ "x86_64-linux" ] "nixos.tests.installer-systemd-stage-1.zfsroot") + (onSystems [ "x86_64-linux" ] "nixos.tests.nixos-rebuild-specialisations") + # Scripted stage 1 installer tests, remove in 26.11 (onSystems [ "aarch64-linux" ] "nixos.tests.installer.simpleUefiSystemdBoot") (onSystems [ "x86_64-linux" ] "nixos.tests.installer.btrfsSimple") (onSystems [ "x86_64-linux" ] "nixos.tests.installer.btrfsSubvolDefault") @@ -166,6 +184,8 @@ rec { (onFullSupported "nixos.tests.nfs4.simple") (onSystems [ "x86_64-linux" ] "nixos.tests.oci-containers.podman") (onFullSupported "nixos.tests.openssh") + (onFullSupported "nixos.tests.systemd-initrd-networkd-ssh") + # Scripted stage 1 SSH test, remove in 26.11 (onFullSupported "nixos.tests.initrd-network-ssh") (onFullSupported "nixos.tests.pantheon") (onFullSupported "nixos.tests.php.fpm") diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix index 5dc1b20b0293..9a059c30563c 100644 --- a/nixos/tests/all-tests.nix +++ b/nixos/tests/all-tests.nix @@ -727,7 +727,9 @@ in # 9pnet_virtio used to mount /nix partition doesn't support # hibernation. This test happens to work on x86_64-linux but # not on other platforms. - hibernate = handleTestOn [ "x86_64-linux" ] ./hibernate.nix { }; + hibernate = handleTestOn [ "x86_64-linux" ] ./hibernate.nix { + systemdStage1 = false; + }; hibernate-systemd-stage-1 = handleTestOn [ "x86_64-linux" ] ./hibernate.nix { systemdStage1 = true; }; @@ -769,8 +771,13 @@ in }; influxdb = runTest ./influxdb.nix; influxdb2 = runTest ./influxdb2.nix; - initrd-luks-empty-passphrase = runTest ./initrd-luks-empty-passphrase.nix; - initrd-network-openvpn = handleTestOn [ "x86_64-linux" "i686-linux" ] ./initrd-network-openvpn { }; + initrd-luks-empty-passphrase = runTest { + imports = [ ./initrd-luks-empty-passphrase.nix ]; + _module.args.systemdStage1 = false; + }; + initrd-network-openvpn = handleTestOn [ "x86_64-linux" "i686-linux" ] ./initrd-network-openvpn { + systemdStage1 = false; + }; initrd-network-ssh = handleTest ./initrd-network-ssh { }; initrd-secrets = handleTest ./initrd-secrets.nix { }; initrd-secrets-changing = handleTest ./initrd-secrets-changing.nix { }; @@ -778,8 +785,8 @@ in input-remapper = runTest ./input-remapper.nix; inspircd = runTest ./inspircd.nix; installed-tests = recurseIntoAttrs (handleTest ./installed-tests { }); - installer = handleTest ./installer.nix { }; - installer-systemd-stage-1 = handleTest ./installer-systemd-stage-1.nix { }; + installer = handleTest ./installer.nix { systemdStage1 = false; }; + installer-systemd-stage-1 = handleTest ./installer.nix { systemdStage1 = true; }; intune = runTest ./intune.nix; invidious = runTest ./invidious.nix; invoiceplane = runTest ./invoiceplane.nix; @@ -1603,7 +1610,10 @@ in systemd-pstore = runTest ./systemd-pstore.nix; systemd-repart = handleTest ./systemd-repart.nix { }; systemd-resolved = runTest ./systemd-resolved.nix; - systemd-shutdown = runTest ./systemd-shutdown.nix; + systemd-shutdown = runTest { + imports = [ ./systemd-shutdown.nix ]; + _module.args.systemdStage1 = false; + }; systemd-ssh-proxy = runTest ./systemd-ssh-proxy.nix; systemd-sysupdate = runTest ./systemd-sysupdate.nix; systemd-sysusers-immutable = runTest ./systemd-sysusers-immutable.nix; diff --git a/nixos/tests/boot-stage1.nix b/nixos/tests/boot-stage1.nix index e76af3e1dc6f..2fda8355086a 100644 --- a/nixos/tests/boot-stage1.nix +++ b/nixos/tests/boot-stage1.nix @@ -1,3 +1,6 @@ +# Remove in 26.11. This test guards against problems with +# stage-1-init.sh, which will be removed with scripted stage 1. + { pkgs, ... }: { name = "boot-stage1"; @@ -10,6 +13,8 @@ ... }: { + boot.initrd.systemd.enable = false; + boot.extraModulePackages = let compileKernelModule = diff --git a/nixos/tests/boot-stage2.nix b/nixos/tests/boot-stage2.nix index c2aa3730ed4b..08c00d46c6c6 100644 --- a/nixos/tests/boot-stage2.nix +++ b/nixos/tests/boot-stage2.nix @@ -54,6 +54,9 @@ boot = { initrd = { + # TODO: Switch to systemd initrd + systemd.enable = false; + # Format the upper Nix store. postDeviceCommands = '' ${pkgs.e2fsprogs}/bin/mkfs.ext4 /dev/vdb diff --git a/nixos/tests/ec2.nix b/nixos/tests/ec2.nix index ae9a79db5403..1a84033ffed5 100644 --- a/nixos/tests/ec2.nix +++ b/nixos/tests/ec2.nix @@ -19,9 +19,13 @@ let ../modules/profiles/qemu-guest.nix { # Hack to make the partition resizing work in QEMU. - boot.initrd.postDeviceCommands = mkBefore '' - ln -s vda /dev/xvda - ln -s vda1 /dev/xvda1 + boot.initrd.services.udev.rules = '' + KERNEL==vda, SYMLINK+=xvda + KERNEL==vda1, SYMLINK+=xvda1 + ''; + services.udev.extraRules = '' + KERNEL==vda, SYMLINK+=xvda + KERNEL==vda1, SYMLINK+=xvda1 ''; amazonImage.format = "qcow2"; diff --git a/nixos/tests/envfs.nix b/nixos/tests/envfs.nix index 78946285ed68..a209b2c8db2c 100644 --- a/nixos/tests/envfs.nix +++ b/nixos/tests/envfs.nix @@ -1,6 +1,6 @@ { pkgs, - systemdStage1 ? false, + systemdStage1, ... }: diff --git a/nixos/tests/hibernate.nix b/nixos/tests/hibernate.nix index 9b840a4e14da..53daec48d6c0 100644 --- a/nixos/tests/hibernate.nix +++ b/nixos/tests/hibernate.nix @@ -4,7 +4,7 @@ system ? builtins.currentSystem, config ? { }, pkgs ? import ../.. { inherit system config; }, - systemdStage1 ? false, + systemdStage1, }: with import ../lib/testing-python.nix { inherit system pkgs; }; diff --git a/nixos/tests/initrd-luks-empty-passphrase.nix b/nixos/tests/initrd-luks-empty-passphrase.nix index 3a906685f0ca..56a92a827ff4 100644 --- a/nixos/tests/initrd-luks-empty-passphrase.nix +++ b/nixos/tests/initrd-luks-empty-passphrase.nix @@ -14,8 +14,6 @@ in { name = "initrd-luks-empty-passphrase"; - _module.args.systemdStage1 = lib.mkDefault false; - nodes.machine = { pkgs, ... }: { @@ -31,9 +29,9 @@ in }; boot.loader.systemd-boot.enable = true; - boot.initrd.systemd = lib.mkIf systemdStage1 { - enable = true; - emergencyAccess = true; + boot.initrd.systemd = { + enable = systemdStage1; + emergencyAccess = lib.mkIf systemdStage1 true; }; environment.systemPackages = with pkgs; [ cryptsetup ]; diff --git a/nixos/tests/initrd-network-openvpn/default.nix b/nixos/tests/initrd-network-openvpn/default.nix index f685e46dc467..0e4edcb4f70c 100644 --- a/nixos/tests/initrd-network-openvpn/default.nix +++ b/nixos/tests/initrd-network-openvpn/default.nix @@ -2,7 +2,7 @@ system ? builtins.currentSystem, config ? { }, pkgs ? import ../.. { inherit system config; }, - systemdStage1 ? false, + systemdStage1, }: import ../make-test-python.nix ( diff --git a/nixos/tests/initrd-network-ssh/default.nix b/nixos/tests/initrd-network-ssh/default.nix index 510a9f7ef4e5..60b888b69a86 100644 --- a/nixos/tests/initrd-network-ssh/default.nix +++ b/nixos/tests/initrd-network-ssh/default.nix @@ -1,3 +1,5 @@ +# This tests SSH in scripted stage 1. Remove in 26.11. + import ../make-test-python.nix ( { lib, pkgs, ... }: @@ -14,6 +16,7 @@ import ../make-test-python.nix ( boot.kernelParams = [ "ip=${config.networking.primaryIPAddress}:::255.255.255.0::eth1:none" ]; + boot.initrd.systemd.enable = false; boot.initrd.network = { enable = true; ssh = { diff --git a/nixos/tests/initrd-network.nix b/nixos/tests/initrd-network.nix index b84588f1d250..b43e62db0a52 100644 --- a/nixos/tests/initrd-network.nix +++ b/nixos/tests/initrd-network.nix @@ -1,3 +1,5 @@ +# Tests networking in scripted stage 1. Remove in 26.11. + { pkgs, lib, ... }: { name = "initrd-network"; @@ -8,6 +10,7 @@ { ... }: { imports = [ ../modules/profiles/minimal.nix ]; + boot.initrd.systemd.enable = false; boot.initrd.network.enable = true; boot.initrd.network.postCommands = '' ip addr show diff --git a/nixos/tests/initrd-secrets-changing.nix b/nixos/tests/initrd-secrets-changing.nix index f0d6bc4c28b4..1ff8a9aabdcb 100644 --- a/nixos/tests/initrd-secrets-changing.nix +++ b/nixos/tests/initrd-secrets-changing.nix @@ -24,14 +24,19 @@ testing.makeTest { boot.initrd.secrets = { "/test" = secret1InStore; - "/run/keys/test" = secret1InStore; + "/run/test" = secret1InStore; + }; + boot.initrd.systemd = { + enable = true; + tmpfiles.settings."00-copy-secret" = { + "/sysroot/secret-from-initramfs".C.argument = "/test"; + }; }; - boot.initrd.postMountCommands = "cp /test /mnt-root/secret-from-initramfs"; specialisation.secrets2System.configuration = { boot.initrd.secrets = lib.mkForce { "/test" = secret2InStore; - "/run/keys/test" = secret2InStore; + "/run/test" = secret2InStore; }; }; }; @@ -40,21 +45,23 @@ testing.makeTest { start_all() machine.wait_for_unit("multi-user.target") - print(machine.succeed("cat /run/keys/test")) + print(machine.succeed("cat /run/test")) machine.succeed( "cmp ${secret1InStore} /secret-from-initramfs", - "cmp ${secret1InStore} /run/keys/test", + "cmp ${secret1InStore} /run/test", ) # Select the second boot entry corresponding to the specialisation secrets2System. machine.succeed("grub-reboot 1") + # Remove the rootfs secret so tmpfiles will copy the new one next time + machine.succeed("rm /secret-from-initramfs") machine.shutdown() with subtest("Check that the specialisation's secrets are distinct despite identical kernels"): machine.wait_for_unit("multi-user.target") - print(machine.succeed("cat /run/keys/test")) + print(machine.succeed("cat /run/test")) machine.succeed( "cmp ${secret2InStore} /secret-from-initramfs", - "cmp ${secret2InStore} /run/keys/test", + "cmp ${secret2InStore} /run/test", ) machine.shutdown() ''; diff --git a/nixos/tests/initrd-secrets.nix b/nixos/tests/initrd-secrets.nix index e19ac4d6f3dc..ce0a54dac6c0 100644 --- a/nixos/tests/initrd-secrets.nix +++ b/nixos/tests/initrd-secrets.nix @@ -24,12 +24,15 @@ let boot.initrd.secrets = { "/test" = secretInStore; - # This should *not* need to be copied in postMountCommands - "/run/keys/test" = secretInStore; + # This should *not* need to be copied + "/run/test" = secretInStore; + }; + boot.initrd.systemd = { + enable = true; + tmpfiles.settings."00-copy-secret" = { + "/sysroot/secret-from-initramfs".C.argument = "/test"; + }; }; - boot.initrd.postMountCommands = '' - cp /test /mnt-root/secret-from-initramfs - ''; boot.initrd.compressor = compressor; # zstd compression is only supported from 5.9 onwards. Remove when 5.10 becomes default. boot.kernelPackages = pkgs.linuxPackages_latest; @@ -40,7 +43,7 @@ let machine.wait_for_unit("multi-user.target") machine.succeed( "cmp ${secretInStore} /secret-from-initramfs", - "cmp ${secretInStore} /run/keys/test", + "cmp ${secretInStore} /run/test", ) ''; }; diff --git a/nixos/tests/installer-systemd-stage-1.nix b/nixos/tests/installer-systemd-stage-1.nix deleted file mode 100644 index d007b3caf397..000000000000 --- a/nixos/tests/installer-systemd-stage-1.nix +++ /dev/null @@ -1,52 +0,0 @@ -{ - system ? builtins.currentSystem, - config ? { }, - pkgs ? import ../.. { inherit system config; }, -}: - -{ - # Some of these tests don't work with systemd stage 1 yet. Uncomment - # them when fixed. - inherit - (import ./installer.nix { - inherit system config pkgs; - systemdStage1 = true; - }) - # bcache - bcachefsSimple - bcachefsEncrypted - btrfsSimple - btrfsSubvolDefault - btrfsSubvolEscape - btrfsSubvols - encryptedFSWithKeyfile - # grub1 - luksroot - luksroot-format1 - luksroot-format2 - lvm - separateBoot - separateBootFat - separateBootZfs - simple - simpleLabels - simpleProvided - simpleSpecialised - simpleUefiGrub - simpleUefiGrubSpecialisation - simpleUefiSystemdBoot - stratisRoot - swraid - zfsroot - clevisLuks - clevisLuksFallback - clevisZfs - clevisZfsFallback - clevisZfsParentDataset - clevisZfsParentDatasetFallback - gptAutoRoot - clevisBcachefs - clevisBcachefsFallback - ; - -} diff --git a/nixos/tests/installer.nix b/nixos/tests/installer.nix index 892c066c568b..80148997bff0 100644 --- a/nixos/tests/installer.nix +++ b/nixos/tests/installer.nix @@ -2,7 +2,7 @@ system ? builtins.currentSystem, config ? { }, pkgs ? import ../.. { inherit system config; }, - systemdStage1 ? false, + systemdStage1, }: with import ../lib/testing-python.nix { inherit system pkgs; }; @@ -42,7 +42,7 @@ let # To ensure that we can rebuild the grub configuration on the nixos-rebuild system.extraDependencies = with pkgs; [ stdenvNoCC ]; - ${optionalString systemdStage1 "boot.initrd.systemd.enable = true;"} + boot.initrd.systemd.enable = ${boolToString systemdStage1}; ${optionalString (bootLoader == "grub") '' boot.loader.grub.extraConfig = "serial; terminal_output serial"; @@ -640,6 +640,7 @@ let clevisFallbackTest ? false, disableFileSystems ? false, selectNixPackage ? pkgs: pkgs.nixVersions.stable, + broken ? false, }: let isEfi = bootLoader == "systemd-boot" || (bootLoader == "grub" && grubUseEfi); @@ -656,6 +657,7 @@ let "x86_64-darwin" "i686-linux" ]; + inherit broken; }; nodes = let @@ -846,14 +848,23 @@ let "mount LABEL=boot /mnt/boot", ) ''; - extraConfig = '' - boot.kernelParams = lib.mkAfter [ "console=tty0" ]; - ''; - enableOCR = true; - postBootCommands = '' - target.wait_for_text("[Pp]assphrase for") - target.send_chars("supersecret\n") - ''; + # The serial console is much more reliable than OCR, but + # scripted stage 1 doesn't forward logs / password prompts to + # it. (TODO: The test framework should use 'console=ttyS0' + # anyway, but currently it uses 'console=tty0' for the sake of + # the interactive driver) + enableOCR = !systemdStage1; + postBootCommands = + if systemdStage1 then + '' + target.wait_for_console_text("passphrase for") + target.send_console("supersecret\n") + '' + else + '' + target.wait_for_text("[Pp]assphrase for") + target.send_chars("supersecret\n") + ''; }; # The (almost) simplest partitioning scheme: a swap partition and @@ -879,11 +890,13 @@ let simple-test-config-by-attr = simple-test-config // { testByAttrSwitch = true; + broken = true; }; simple-test-config-from-by-attr-to-flake = simple-test-config // { testByAttrSwitch = true; testFlakeSwitch = true; + broken = true; }; simple-uefi-grub-config = { @@ -1387,6 +1400,7 @@ in # Full disk encryption (root, kernel and initrd encrypted) using GRUB, GPT/UEFI, # LVM-on-LUKS and a keyfile in initrd.secrets to enter the passphrase once fullDiskEncryption = makeInstallerTest "fullDiskEncryption" { + broken = true; createPartitions = '' installer.succeed( "flock /dev/vda parted --script /dev/vda -- mklabel gpt" diff --git a/nixos/tests/iscsi-multipath-root.nix b/nixos/tests/iscsi-multipath-root.nix index ba17ac64058e..90723bdbb604 100644 --- a/nixos/tests/iscsi-multipath-root.nix +++ b/nixos/tests/iscsi-multipath-root.nix @@ -186,6 +186,7 @@ in boot.initrd.extraFiles."etc/multipath/wwids".source = pkgs.writeText "wwids" "/3600140592b17c3f6b404168b082ceeb7/"; + boot.initrd.systemd.enable = false; boot.iscsi-initiator = { discoverPortal = "target"; name = initiatorName; diff --git a/nixos/tests/iscsi-root.nix b/nixos/tests/iscsi-root.nix index e8c98a39931c..571dbecad244 100644 --- a/nixos/tests/iscsi-root.nix +++ b/nixos/tests/iscsi-root.nix @@ -142,6 +142,8 @@ in }; }; + # No SCSI support in systemd stage 1 at present. + boot.initrd.systemd.enable = false; boot.iscsi-initiator = { discoverPortal = "target"; name = initiatorName; diff --git a/nixos/tests/luks.nix b/nixos/tests/luks.nix index 7440d110ad28..db2672eefdc0 100644 --- a/nixos/tests/luks.nix +++ b/nixos/tests/luks.nix @@ -1,3 +1,5 @@ +# Tests LUKS specifically with scripted stage 1. Remove in 26.11. + { lib, pkgs, ... }: { name = "luks"; @@ -6,6 +8,8 @@ { pkgs, ... }: { + boot.initrd.systemd.enable = false; + # Use systemd-boot virtualisation = { emptyDiskImages = [ diff --git a/nixos/tests/misc.nix b/nixos/tests/misc.nix index 3e296d8d428c..12c0275b3a23 100644 --- a/nixos/tests/misc.nix +++ b/nixos/tests/misc.nix @@ -106,8 +106,7 @@ in assert "machine" == machine.succeed("hostname -s").strip() with subtest("whether systemd-udevd automatically loads modules for our hardware"): - machine.succeed("systemctl start systemd-udev-settle.service") - machine.wait_for_unit("systemd-udev-settle.service") + machine.succeed("udevadm settle --timeout=180") assert "mousedev" in machine.succeed("lsmod") with subtest("whether systemd-tmpfiles-clean works"): diff --git a/nixos/tests/non-default-filesystems.nix b/nixos/tests/non-default-filesystems.nix index d0aeb6bab4a8..efa066dde3b3 100644 --- a/nixos/tests/non-default-filesystems.nix +++ b/nixos/tests/non-default-filesystems.nix @@ -36,66 +36,70 @@ with pkgs.lib; ''; }; - btrfs = makeTest { - name = "non-default-filesystems-btrfs"; + btrfs = + let + disk = "/dev/vda"; + partition = "/dev/disk/by-label/storage"; + in + makeTest { + name = "non-default-filesystems-btrfs"; - nodes.machine = - { - config, - pkgs, - lib, - ... - }: - let - disk = config.virtualisation.rootDevice; - in - { - virtualisation.rootDevice = "/dev/vda"; - virtualisation.useDefaultFilesystems = false; + nodes.machine = + { ... }: + { + virtualisation.rootDevice = disk; + virtualisation.useDefaultFilesystems = false; - boot.initrd.availableKernelModules = [ "btrfs" ]; - boot.supportedFilesystems = [ "btrfs" ]; - - boot.initrd.postDeviceCommands = '' - FSTYPE=$(blkid -o value -s TYPE ${disk} || true) - if test -z "$FSTYPE"; then - modprobe btrfs - ${pkgs.btrfs-progs}/bin/mkfs.btrfs ${disk} - - mkdir /nixos - mount -t btrfs ${disk} /nixos - - ${pkgs.btrfs-progs}/bin/btrfs subvolume create /nixos/root - ${pkgs.btrfs-progs}/bin/btrfs subvolume create /nixos/home - - umount /nixos - fi - ''; - - virtualisation.fileSystems = { - "/" = { - device = disk; - fsType = "btrfs"; - options = [ "subvol=/root" ]; + systemd.repart.partitions."00-root" = { + Type = "linux-generic"; + Format = "btrfs"; + Label = "storage"; + Subvolumes = [ + "/root" + "/home" + ]; + MakeDirectories = [ + "/root" + "/home" + ]; }; - "/home" = { - device = disk; - fsType = "btrfs"; - options = [ "subvol=/home" ]; + boot.initrd.supportedFilesystems = [ "btrfs" ]; + + boot.initrd.systemd = { + enable = true; + repart = { + enable = true; + device = disk; + empty = "allow"; + }; + }; + + virtualisation.fileSystems = { + "/" = { + device = partition; + fsType = "btrfs"; + options = [ "subvol=/root" ]; + }; + + "/home" = { + device = partition; + fsType = "btrfs"; + options = [ "subvol=/home" ]; + }; }; }; - }; - testScript = '' - machine.wait_for_unit("multi-user.target") + testScript = '' + machine.wait_for_unit("multi-user.target") - with subtest("BTRFS filesystems are mounted correctly"): - print("output of \"grep -E '/dev/vda' /proc/mounts\":\n" + machine.execute("grep -E '/dev/vda' /proc/mounts")[1]) - machine.succeed("grep -E '/dev/vda / btrfs rw,.*subvolid=[0-9]+,subvol=/root 0 0' /proc/mounts") - machine.succeed("grep -E '/dev/vda /home btrfs rw,.*subvolid=[0-9]+,subvol=/home 0 0' /proc/mounts") - ''; - }; + with subtest("BTRFS filesystems are mounted correctly"): + realdev = machine.succeed("realpath '${partition}'") + print(f"output of \"grep -E '{realdev}' /proc/mounts\":\n" + machine.execute(f"grep -E '{realdev}' /proc/mounts")[1]) + machine.succeed(f"grep -E '{realdev} / btrfs rw,.*subvolid=[0-9]+,subvol=/root 0 0' /proc/mounts") + machine.succeed(f"grep -E '{realdev} /home btrfs rw,.*subvolid=[0-9]+,subvol=/home 0 0' /proc/mounts") + ''; + }; erofs = let diff --git a/nixos/tests/predictable-interface-names.nix b/nixos/tests/predictable-interface-names.nix index 8ab29a73cd4f..6282c433bae7 100644 --- a/nixos/tests/predictable-interface-names.nix +++ b/nixos/tests/predictable-interface-names.nix @@ -43,9 +43,10 @@ pkgs.lib.listToAttrs ( meta = { }; nodes.machine = - { lib, ... }: + { pkgs, lib, ... }: let script = '' + ${lib.getExe' pkgs.systemd "udevadm"} settle --timeout=180 ip link if ${lib.optionalString predictable "!"} ip link show eth0; then echo Success @@ -63,18 +64,20 @@ pkgs.lib.listToAttrs ( # Check if predictable interface names are working in stage-1 boot.initrd.postDeviceCommands = lib.mkIf (!systemdStage1) script; - boot.initrd.systemd = lib.mkIf systemdStage1 { - enable = true; - initrdBin = [ pkgs.iproute2 ]; - services.systemd-udev-settle.wantedBy = [ "initrd.target" ]; - services.check-interfaces = { - requiredBy = [ "initrd.target" ]; - after = [ "systemd-udev-settle.service" ]; - serviceConfig.Type = "oneshot"; - path = [ pkgs.iproute2 ]; - inherit script; - }; - }; + boot.initrd.systemd = lib.mkMerge [ + { enable = systemdStage1; } + (lib.mkIf systemdStage1 { + initrdBin = [ pkgs.iproute2 ]; + services.systemd-udev-settle.wantedBy = [ "initrd.target" ]; + services.check-interfaces = { + requiredBy = [ "initrd.target" ]; + after = [ "systemd-udev-settle.service" ]; + serviceConfig.Type = "oneshot"; + path = [ pkgs.iproute2 ]; + inherit script; + }; + }) + ]; }; testScript = '' diff --git a/nixos/tests/qemu-vm-external-disk-image.nix b/nixos/tests/qemu-vm-external-disk-image.nix index 5c12921f6c56..160ec1945140 100644 --- a/nixos/tests/qemu-vm-external-disk-image.nix +++ b/nixos/tests/qemu-vm-external-disk-image.nix @@ -33,7 +33,7 @@ let label = rootFslabel; partitionTableType = "efi"; format = "qcow2"; - bootSize = "32M"; + bootSize = "128M"; additionalSpace = "0M"; copyChannel = false; }; diff --git a/nixos/tests/swap-partition.nix b/nixos/tests/swap-partition.nix index d6310be61202..fa370be079c8 100644 --- a/nixos/tests/swap-partition.nix +++ b/nixos/tests/swap-partition.nix @@ -1,33 +1,35 @@ -{ lib, pkgs, ... }: +{ ... }: { name = "swap-partition"; nodes.machine = - { - config, - pkgs, - lib, - ... - }: + { config, ... }: { virtualisation.useDefaultFilesystems = false; virtualisation.rootDevice = "/dev/vda1"; - boot.initrd.postDeviceCommands = '' - if ! test -b /dev/vda1; then - ${pkgs.parted}/bin/parted --script /dev/vda -- mklabel msdos - ${pkgs.parted}/bin/parted --script /dev/vda -- mkpart primary 1MiB -250MiB - ${pkgs.parted}/bin/parted --script /dev/vda -- mkpart primary -250MiB 100% - sync - fi - - FSTYPE=$(blkid -o value -s TYPE /dev/vda1 || true) - if test -z "$FSTYPE"; then - ${pkgs.e2fsprogs}/bin/mke2fs -t ext4 -L root /dev/vda1 - ${pkgs.util-linux}/bin/mkswap --label swap /dev/vda2 - fi - ''; + boot.initrd.systemd = { + enable = true; + repart = { + enable = true; + device = "/dev/vda"; + empty = "allow"; + }; + }; + systemd.repart.partitions = { + "00-root" = { + Type = "linux-generic"; + Format = "ext4"; + Label = "root"; + }; + "10-swap" = { + Type = "linux-generic"; + Label = "swap"; + SizeMinBytes = "250M"; + SizeMaxBytes = "250M"; + }; + }; virtualisation.fileSystems = { "/" = { @@ -38,7 +40,8 @@ swapDevices = [ { - device = "/dev/disk/by-label/swap"; + device = "/dev/disk/by-partlabel/swap"; + options = [ "x-systemd.makefs" ]; } ]; }; diff --git a/nixos/tests/swap-random-encryption.nix b/nixos/tests/swap-random-encryption.nix index 80601e89d108..f977104d8dff 100644 --- a/nixos/tests/swap-random-encryption.nix +++ b/nixos/tests/swap-random-encryption.nix @@ -1,14 +1,9 @@ -{ lib, pkgs, ... }: +{ ... }: { name = "swap-random-encryption"; nodes.machine = - { - config, - pkgs, - lib, - ... - }: + { pkgs, ... }: { environment.systemPackages = [ pkgs.cryptsetup ]; @@ -16,19 +11,27 @@ virtualisation.rootDevice = "/dev/vda1"; - boot.initrd.postDeviceCommands = '' - if ! test -b /dev/vda1; then - ${pkgs.parted}/bin/parted --script /dev/vda -- mklabel msdos - ${pkgs.parted}/bin/parted --script /dev/vda -- mkpart primary 1MiB -250MiB - ${pkgs.parted}/bin/parted --script /dev/vda -- mkpart primary -250MiB 100% - sync - fi - - FSTYPE=$(blkid -o value -s TYPE /dev/vda1 || true) - if test -z "$FSTYPE"; then - ${pkgs.e2fsprogs}/bin/mke2fs -t ext4 -L root /dev/vda1 - fi - ''; + boot.initrd.systemd = { + enable = true; + repart = { + enable = true; + device = "/dev/vda"; + empty = "allow"; + }; + }; + systemd.repart.partitions = { + "00-root" = { + Type = "linux-generic"; + Format = "ext4"; + Label = "root"; + }; + "10-swap" = { + Type = "linux-generic"; + Label = "swap"; + SizeMinBytes = "250M"; + SizeMaxBytes = "250M"; + }; + }; virtualisation.fileSystems = { "/" = { @@ -39,7 +42,7 @@ swapDevices = [ { - device = "/dev/vda2"; + device = "/dev/disk/by-partlabel/swap"; randomEncryption = { enable = true; @@ -60,7 +63,7 @@ with subtest("Swap device has 4k sector size"): import json - result = json.loads(machine.succeed("lsblk -Jo PHY-SEC,LOG-SEC /dev/mapper/dev-vda2")) + result = json.loads(machine.succeed("lsblk -Jo PHY-SEC,LOG-SEC /dev/mapper/dev-disk-by\\x2dpartlabel-swap")) block_devices = result["blockdevices"] if len(block_devices) != 1: raise Exception ("lsblk output did not report exactly one block device") @@ -72,7 +75,7 @@ with subtest("Swap encrypt has assigned cipher and keysize"): import re - results = machine.succeed("cryptsetup status dev-vda2").splitlines() + results = machine.succeed("cryptsetup status dev-disk-by\\x2dpartlabel-swap").splitlines() cipher_pattern = re.compile(r"\s*cipher:\s+aes-xts-plain64\s*") if not any(cipher_pattern.fullmatch(line) for line in results): diff --git a/nixos/tests/systemd-misc.nix b/nixos/tests/systemd-misc.nix index 2623f78add63..30f9fe720059 100644 --- a/nixos/tests/systemd-misc.nix +++ b/nixos/tests/systemd-misc.nix @@ -60,5 +60,10 @@ in machine.succeed("systemctl status example.service | grep 'Active: active'") machine.succeed("systemctl show --property TasksMax --value user-1000.slice | grep 100") + + with subtest("modprobe@ services work"): + modprobe_service_status = machine.succeed("systemctl show --property ExecMainStatus modprobe@configfs.service") + print(modprobe_service_status) + t.assertEqual("ExecMainStatus=0\n", modprobe_service_status) ''; } diff --git a/nixos/tests/systemd-shutdown.nix b/nixos/tests/systemd-shutdown.nix index 827cbac300d8..7439c9331182 100644 --- a/nixos/tests/systemd-shutdown.nix +++ b/nixos/tests/systemd-shutdown.nix @@ -11,8 +11,6 @@ in name = "systemd-shutdown"; meta.maintainers = with lib.maintainers; [ das_j ]; - _module.args.systemdStage1 = lib.mkDefault false; - nodes.machine = { imports = [ ../modules/profiles/minimal.nix ]; systemd.shutdownRamfs.contents."/etc/systemd/system-shutdown/shutdown-message".source = diff --git a/pkgs/by-name/ru/ruff/package.nix b/pkgs/by-name/ru/ruff/package.nix index 1b7deaaa92d7..6241410abaf8 100644 --- a/pkgs/by-name/ru/ruff/package.nix +++ b/pkgs/by-name/ru/ruff/package.nix @@ -16,18 +16,18 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "ruff"; - version = "0.15.9"; + version = "0.15.10"; src = fetchFromGitHub { owner = "astral-sh"; repo = "ruff"; tag = finalAttrs.version; - hash = "sha256-ePivGE8izhG1fj6efV/UdN8P/KdWVCUGCYGP9abLN5w="; + hash = "sha256-x+zqgIJATDWimxbh/VGt94HFiUSD4H9QD/49hnHgfuQ="; }; cargoBuildFlags = [ "--package=ruff" ]; - cargoHash = "sha256-DCTFjFl/fCbXwj7AGPNnrjvSTqxNW6PVWsUhbSGe/wI="; + cargoHash = "sha256-EQERi5NSMUK7qfFYWilzhacYlK4ShQl9Koz8t/8I6+U="; nativeBuildInputs = [ installShellFiles ]; diff --git a/pkgs/os-specific/linux/kernel/common-config.nix b/pkgs/os-specific/linux/kernel/common-config.nix index 70dfebee57b9..6d1015afdcfe 100644 --- a/pkgs/os-specific/linux/kernel/common-config.nix +++ b/pkgs/os-specific/linux/kernel/common-config.nix @@ -825,6 +825,8 @@ let whenOlder "6.2" yes ); # allow RDRAND to seed the RNG RANDOM_TRUST_BOOTLOADER = whenOlder "6.2" yes; # allow the bootloader to seed the RNG + # only when compiled as yes, TPM 2.0 will automatically seed the kernel RNG + HW_RANDOM = yes; MODULE_SIG = no; # r13y, generates a random key during build and bakes it in # Depends on MODULE_SIG and only really helps when you sign your modules diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index adf23aea9dbc..d0581ef08f29 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -1,12 +1,12 @@ { "testing": { - "version": "7.0-rc6", - "hash": "sha256:085bc06mbav64rmsm6a34j2y75nrqpqp4qd8ld8mb9acf1i4iw45", + "version": "7.0-rc7", + "hash": "sha256:0d4199hy9z3md6ia1p2awy89y2fqpwvgadn0j850f4xckz2hqdgf", "lts": false }, "6.1": { - "version": "6.1.167", - "hash": "sha256:1jwqwp2fg3wdsh9w663rbnbv1rvsvksv1pj4bzns8swp0wy0a618", + "version": "6.1.168", + "hash": "sha256:0vkp75sfnjvfqxjh6gqcx24h2m6qj6xkwlw6b118cja43vjnz1g0", "lts": true }, "5.15": { @@ -20,23 +20,23 @@ "lts": true }, "6.6": { - "version": "6.6.132", - "hash": "sha256:1d1fdd5wpphlm68yb16csaaijv0lf38ynl3gpvvdspsg22xjpdn5", + "version": "6.6.134", + "hash": "sha256:1grp1wqgzjsk6xyl0nvd2hxlxjj0wgz04x544zkz8srp6rxnjy33", "lts": true }, "6.12": { - "version": "6.12.80", - "hash": "sha256:0lrylj87bb8ky29pbplpncrfhmgqqbq3d49iqgdwv7p7jvc929f9", + "version": "6.12.81", + "hash": "sha256:0iw84bqdbh9dlaqd1bqgldg50riw2b5is7ipqnbp0sll8cv9rc62", "lts": true }, "6.18": { - "version": "6.18.21", - "hash": "sha256:0ks735y6jq4yy3jaicjsj4dn4n3kk2skf9dqh9dyifipn57j2f0w", + "version": "6.18.22", + "hash": "sha256:0nazlm6j5blyd4qgl0z6xc3qk00vz3cfvx5mqv18awv5ygx94g52", "lts": true }, "6.19": { - "version": "6.19.11", - "hash": "sha256:16ymkc5r3hw05z7l7ih3qw406qlszz1l7b4g5yz0hv15ddxrs0r0", + "version": "6.19.12", + "hash": "sha256:1md8b270pdyk9d8cq0qyr8qmymcijmj3gc39nn394wpr0l94yp6f", "lts": false } }