nixos/gonic: fix writeability of paths from config (#463848)

This commit is contained in:
Paul Meyer
2025-11-24 07:19:13 +00:00
committed by GitHub
2 changed files with 48 additions and 7 deletions
+3 -2
View File
@@ -21,6 +21,8 @@ in
enable = lib.mkEnableOption "Gonic music server";
package = lib.mkPackageOption pkgs "gonic" { };
settings = lib.mkOption rec {
type = settingsFormat.type;
apply = lib.recursiveUpdate default;
@@ -62,8 +64,7 @@ in
n: v: !((n == "tls-cert" || n == "tls-key") && v == null)
) cfg.settings;
in
"${pkgs.gonic}/bin/gonic -config-path ${settingsFormat.generate "gonic" filteredSettings}";
DynamicUser = true;
"${lib.getExe cfg.package} -config-path ${settingsFormat.generate "gonic" filteredSettings}";
StateDirectory = "gonic";
CacheDirectory = "gonic";
WorkingDirectory = "/var/lib/gonic";
+45 -5
View File
@@ -1,19 +1,34 @@
{ pkgs, ... }:
{ lib, pkgs, ... }:
{
name = "gonic";
meta.maintainers = pkgs.gonic.meta.maintainers;
nodes.machine =
{ ... }:
nodes.default_cache_dir =
{ config, ... }:
{
systemd.tmpfiles.settings = {
"10-gonic" = {
"/tmp/music"."d" = { };
"/tmp/podcast"."d" = { };
"/tmp/playlists"."d" = { };
"/tmp/secrets"."d" = { };
};
};
services.gonic = {
enable = true;
# Wrap gonic to check that the required paths are writable.
# This isn't necessarily checked by successful service startup.
package = pkgs.writeShellApplication {
name = "gonic-test-wrapper";
runtimeInputs = [ pkgs.gonic ];
text = ''
touch ${config.services.gonic.settings.cache-path}/foo && echo "cache dir writeable" >&2
touch /tmp/podcast/foo && echo "podcast dir writeable" >&2
touch /tmp/playlists/foo && echo "playlists dir writeable" >&2
touch /tmp/secrets/foo && echo "shouldn't be able to write /tmp/secrets" >&2 && exit 1
exec ${lib.getExe pkgs.gonic} "$@"
'';
};
settings = {
music-path = [ "/tmp/music" ];
podcast-path = "/tmp/podcast";
@@ -22,8 +37,33 @@
};
};
nodes.custom_cache_dir =
{ ... }:
{
systemd.tmpfiles.settings = {
"10-gonic" = {
"/tmp/music"."d" = { };
"/tmp/podcast"."d" = { };
"/tmp/playlists"."d" = { };
"/tmp/cache"."d" = { };
};
};
services.gonic = {
enable = true;
settings = {
music-path = [ "/tmp/music" ];
podcast-path = "/tmp/podcast";
playlists-path = "/tmp/playlists";
cache-path = "/tmp/cache";
};
};
};
testScript = ''
machine.wait_for_unit("gonic")
machine.wait_for_open_port(4747)
default_cache_dir.wait_for_unit("gonic")
default_cache_dir.wait_for_open_port(4747)
custom_cache_dir.wait_for_unit("gonic")
custom_cache_dir.wait_for_open_port(4747)
'';
}