2018-07-20 21:56:59 +01:00
|
|
|
{ config, lib, pkgs, ... }:
|
2008-03-06 17:11:22 +00:00
|
|
|
|
2014-04-14 15:26:48 +01:00
|
|
|
with lib;
|
2008-11-23 01:28:58 +00:00
|
|
|
|
|
|
|
let
|
|
|
|
cfg = config.services.avahi;
|
|
|
|
|
2017-04-09 00:57:32 +01:00
|
|
|
yesNo = yes : if yes then "yes" else "no";
|
|
|
|
|
2009-10-12 17:36:19 +01:00
|
|
|
avahiDaemonConf = with cfg; pkgs.writeText "avahi-daemon.conf" ''
|
2008-03-06 17:11:22 +00:00
|
|
|
[server]
|
2012-09-07 09:58:53 +01:00
|
|
|
${# Users can set `networking.hostName' to the empty string, when getting
|
|
|
|
# a host name from DHCP. In that case, let Avahi take whatever the
|
|
|
|
# current host name is; setting `host-name' to the empty string in
|
|
|
|
# `avahi-daemon.conf' would be invalid.
|
2017-04-09 00:57:32 +01:00
|
|
|
optionalString (hostName != "") "host-name=${hostName}"}
|
2009-10-12 17:36:19 +01:00
|
|
|
browse-domains=${concatStringsSep ", " browseDomains}
|
2017-04-09 00:57:32 +01:00
|
|
|
use-ipv4=${yesNo ipv4}
|
|
|
|
use-ipv6=${yesNo ipv6}
|
2015-12-21 16:28:44 +00:00
|
|
|
${optionalString (interfaces!=null) "allow-interfaces=${concatStringsSep "," interfaces}"}
|
2016-05-29 02:01:47 +01:00
|
|
|
${optionalString (domainName!=null) "domain-name=${domainName}"}
|
2017-04-09 00:57:32 +01:00
|
|
|
allow-point-to-point=${yesNo allowPointToPoint}
|
2017-07-12 13:23:15 +01:00
|
|
|
${optionalString (cacheEntriesMax!=null) "cache-entries-max=${toString cacheEntriesMax}"}
|
2008-03-06 17:11:22 +00:00
|
|
|
|
|
|
|
[wide-area]
|
2017-04-09 00:57:32 +01:00
|
|
|
enable-wide-area=${yesNo wideArea}
|
2008-03-06 17:11:22 +00:00
|
|
|
|
|
|
|
[publish]
|
2017-04-09 00:57:32 +01:00
|
|
|
disable-publishing=${yesNo (!publish.enable)}
|
|
|
|
disable-user-service-publishing=${yesNo (!publish.userServices)}
|
|
|
|
publish-addresses=${yesNo (publish.userServices || publish.addresses)}
|
|
|
|
publish-hinfo=${yesNo publish.hinfo}
|
|
|
|
publish-workstation=${yesNo publish.workstation}
|
|
|
|
publish-domain=${yesNo publish.domain}
|
2017-04-18 14:10:24 +01:00
|
|
|
|
|
|
|
[reflector]
|
|
|
|
enable-reflector=${yesNo reflector}
|
2018-07-28 10:48:08 +01:00
|
|
|
${extraConfig}
|
2008-03-06 17:11:22 +00:00
|
|
|
'';
|
2009-10-12 17:36:19 +01:00
|
|
|
in
|
|
|
|
{
|
2019-05-22 19:59:34 +01:00
|
|
|
options.services.avahi = {
|
|
|
|
enable = mkOption {
|
|
|
|
type = types.bool;
|
|
|
|
default = false;
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc ''
|
2019-05-22 19:59:34 +01:00
|
|
|
Whether to run the Avahi daemon, which allows Avahi clients
|
|
|
|
to use Avahi's service discovery facilities and also allows
|
|
|
|
the local machine to advertise its presence and services
|
|
|
|
(through the mDNS responder implemented by `avahi-daemon').
|
|
|
|
'';
|
|
|
|
};
|
2008-11-23 01:28:58 +00:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
hostName = mkOption {
|
|
|
|
type = types.str;
|
|
|
|
default = config.networking.hostName;
|
2021-10-03 17:06:03 +01:00
|
|
|
defaultText = literalExpression "config.networking.hostName";
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc ''
|
2019-05-22 19:59:34 +01:00
|
|
|
Host name advertised on the LAN. If not set, avahi will use the value
|
2022-07-28 22:19:15 +01:00
|
|
|
of {option}`config.networking.hostName`.
|
2019-05-22 19:59:34 +01:00
|
|
|
'';
|
|
|
|
};
|
2008-11-23 01:28:58 +00:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
domainName = mkOption {
|
|
|
|
type = types.str;
|
|
|
|
default = "local";
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc ''
|
2019-05-22 19:59:34 +01:00
|
|
|
Domain name for all advertisements.
|
|
|
|
'';
|
|
|
|
};
|
2011-09-14 19:20:50 +01:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
browseDomains = mkOption {
|
|
|
|
type = types.listOf types.str;
|
|
|
|
default = [ ];
|
|
|
|
example = [ "0pointer.de" "zeroconf.org" ];
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc ''
|
2019-05-22 19:59:34 +01:00
|
|
|
List of non-local DNS domains to be browsed.
|
|
|
|
'';
|
|
|
|
};
|
2009-10-12 17:36:19 +01:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
ipv4 = mkOption {
|
|
|
|
type = types.bool;
|
|
|
|
default = true;
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Whether to use IPv4.";
|
2019-05-22 19:59:34 +01:00
|
|
|
};
|
2009-07-01 13:27:35 +01:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
ipv6 = mkOption {
|
|
|
|
type = types.bool;
|
2020-10-26 03:01:07 +00:00
|
|
|
default = config.networking.enableIPv6;
|
2021-10-03 17:06:03 +01:00
|
|
|
defaultText = literalExpression "config.networking.enableIPv6";
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Whether to use IPv6.";
|
2019-05-22 19:59:34 +01:00
|
|
|
};
|
2009-07-01 13:27:35 +01:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
interfaces = mkOption {
|
|
|
|
type = types.nullOr (types.listOf types.str);
|
|
|
|
default = null;
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc ''
|
|
|
|
List of network interfaces that should be used by the {command}`avahi-daemon`.
|
|
|
|
Other interfaces will be ignored. If `null`, all local interfaces
|
2019-05-22 19:59:34 +01:00
|
|
|
except loopback and point-to-point will be used.
|
|
|
|
'';
|
|
|
|
};
|
2016-05-29 02:01:47 +01:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
openFirewall = mkOption {
|
|
|
|
type = types.bool;
|
2022-12-10 02:40:39 +00:00
|
|
|
default = true;
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc ''
|
2019-05-22 19:59:34 +01:00
|
|
|
Whether to open the firewall for UDP port 5353.
|
2022-12-10 02:40:39 +00:00
|
|
|
Disabling this setting also disables discovering of network devices.
|
2019-05-22 19:59:34 +01:00
|
|
|
'';
|
|
|
|
};
|
2008-03-06 17:11:22 +00:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
allowPointToPoint = mkOption {
|
|
|
|
type = types.bool;
|
|
|
|
default = false;
|
2022-12-10 02:40:39 +00:00
|
|
|
description = lib.mdDoc ''
|
2019-05-22 19:59:34 +01:00
|
|
|
Whether to use POINTTOPOINT interfaces. Might make mDNS unreliable due to usually large
|
|
|
|
latencies with such links and opens a potential security hole by allowing mDNS access from Internet
|
|
|
|
connections.
|
|
|
|
'';
|
|
|
|
};
|
2008-03-06 20:56:50 +00:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
wideArea = mkOption {
|
|
|
|
type = types.bool;
|
|
|
|
default = true;
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Whether to enable wide-area service discovery.";
|
2019-05-22 19:59:34 +01:00
|
|
|
};
|
2008-11-23 01:28:58 +00:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
reflector = mkOption {
|
|
|
|
type = types.bool;
|
|
|
|
default = false;
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Reflect incoming mDNS requests to all allowed network interfaces.";
|
2019-05-22 19:59:34 +01:00
|
|
|
};
|
2015-12-21 16:28:44 +00:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
extraServiceFiles = mkOption {
|
|
|
|
type = with types; attrsOf (either str path);
|
|
|
|
default = {};
|
2021-10-03 17:06:03 +01:00
|
|
|
example = literalExpression ''
|
2019-05-22 19:59:34 +01:00
|
|
|
{
|
|
|
|
ssh = "''${pkgs.avahi}/etc/avahi/services/ssh.service";
|
|
|
|
smb = '''
|
|
|
|
<?xml version="1.0" standalone='no'?><!--*-nxml-*-->
|
|
|
|
<!DOCTYPE service-group SYSTEM "avahi-service.dtd">
|
|
|
|
<service-group>
|
|
|
|
<name replace-wildcards="yes">%h</name>
|
|
|
|
<service>
|
|
|
|
<type>_smb._tcp</type>
|
|
|
|
<port>445</port>
|
|
|
|
</service>
|
|
|
|
</service-group>
|
|
|
|
''';
|
|
|
|
}
|
|
|
|
'';
|
2022-08-05 18:39:00 +01:00
|
|
|
description = lib.mdDoc ''
|
2019-05-22 19:59:34 +01:00
|
|
|
Specify custom service definitions which are placed in the avahi service directory.
|
2022-08-05 18:39:00 +01:00
|
|
|
See the {manpage}`avahi.service(5)` manpage for detailed information.
|
2019-05-22 19:59:34 +01:00
|
|
|
'';
|
|
|
|
};
|
2017-02-28 13:10:52 +00:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
publish = {
|
|
|
|
enable = mkOption {
|
|
|
|
type = types.bool;
|
|
|
|
default = false;
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Whether to allow publishing in general.";
|
2009-10-12 17:36:19 +01:00
|
|
|
};
|
2008-11-23 01:28:58 +00:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
userServices = mkOption {
|
|
|
|
type = types.bool;
|
2017-04-18 14:10:24 +01:00
|
|
|
default = false;
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Whether to publish user services. Will set `addresses=true`.";
|
2017-04-18 14:10:24 +01:00
|
|
|
};
|
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
addresses = mkOption {
|
|
|
|
type = types.bool;
|
|
|
|
default = false;
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Whether to register mDNS address records for all local IP addresses.";
|
2009-10-12 17:36:19 +01:00
|
|
|
};
|
2008-03-06 17:11:22 +00:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
hinfo = mkOption {
|
|
|
|
type = types.bool;
|
2009-10-12 17:36:19 +01:00
|
|
|
default = false;
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc ''
|
2019-05-22 19:59:34 +01:00
|
|
|
Whether to register a mDNS HINFO record which contains information about the
|
|
|
|
local operating system and CPU.
|
2009-10-12 17:36:19 +01:00
|
|
|
'';
|
|
|
|
};
|
2011-09-14 19:20:50 +01:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
workstation = mkOption {
|
|
|
|
type = types.bool;
|
|
|
|
default = false;
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc ''
|
2019-05-22 19:59:34 +01:00
|
|
|
Whether to register a service of type "_workstation._tcp" on the local LAN.
|
2017-07-12 13:23:15 +01:00
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
domain = mkOption {
|
|
|
|
type = types.bool;
|
|
|
|
default = false;
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Whether to announce the locally used domain name for browsing by other hosts.";
|
2018-07-28 10:48:08 +01:00
|
|
|
};
|
2008-11-23 01:28:58 +00:00
|
|
|
};
|
2011-09-14 19:20:50 +01:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
nssmdns = mkOption {
|
|
|
|
type = types.bool;
|
|
|
|
default = false;
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc ''
|
2019-05-22 19:59:34 +01:00
|
|
|
Whether to enable the mDNS NSS (Name Service Switch) plug-in.
|
|
|
|
Enabling it allows applications to resolve names in the `.local'
|
|
|
|
domain by transparently querying the Avahi daemon.
|
|
|
|
'';
|
|
|
|
};
|
2011-09-14 19:20:50 +01:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
cacheEntriesMax = mkOption {
|
|
|
|
type = types.nullOr types.int;
|
|
|
|
default = null;
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc ''
|
2019-05-22 19:59:34 +01:00
|
|
|
Number of resource records to be cached per interface. Use 0 to
|
|
|
|
disable caching. Avahi daemon defaults to 4096 if not set.
|
|
|
|
'';
|
|
|
|
};
|
2009-10-12 17:36:19 +01:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
extraConfig = mkOption {
|
|
|
|
type = types.lines;
|
|
|
|
default = "";
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc ''
|
2019-05-22 19:59:34 +01:00
|
|
|
Extra config to append to avahi-daemon.conf.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
};
|
2009-10-12 17:36:19 +01:00
|
|
|
|
|
|
|
config = mkIf cfg.enable {
|
2019-05-22 19:59:34 +01:00
|
|
|
users.users.avahi = {
|
|
|
|
description = "avahi-daemon privilege separation user";
|
|
|
|
home = "/var/empty";
|
|
|
|
group = "avahi";
|
|
|
|
isSystemUser = true;
|
|
|
|
};
|
2009-10-12 17:36:19 +01:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
users.groups.avahi = {};
|
2009-10-12 17:36:19 +01:00
|
|
|
|
|
|
|
system.nssModules = optional cfg.nssmdns pkgs.nssmdns;
|
2020-05-05 23:17:05 +01:00
|
|
|
system.nssDatabases.hosts = optionals cfg.nssmdns (mkMerge [
|
nixos/systemd: fix NSS database ordering
- The order of NSS (host) modules has been brought in line with upstream
recommendations:
- The `myhostname` module is placed before the `resolve` (optional) and `dns`
entries, but after `file` (to allow overriding via `/etc/hosts` /
`networking.extraHosts`, and prevent ISPs with catchall-DNS resolvers from
hijacking `.localhost` domains)
- The `mymachines` module, which provides hostname resolution for local
containers (registered with `systemd-machined`) is placed to the front, to
make sure its mappings are preferred over other resolvers.
- If systemd-networkd is enabled, the `resolve` module is placed before
`files` and `myhostname`, as it provides the same logic internally, with
caching.
- The `mdns(_minimal)` module has been updated to the new priorities.
If you use your own NSS host modules, make sure to update your priorities
according to these rules:
- NSS modules which should be queried before `resolved` DNS resolution should
use mkBefore.
- NSS modules which should be queried after `resolved`, `files` and
`myhostname`, but before `dns` should use the default priority
- NSS modules which should come after `dns` should use mkAfter.
2021-07-17 18:41:45 +01:00
|
|
|
(mkBefore [ "mdns_minimal [NOTFOUND=return]" ]) # before resolve
|
|
|
|
(mkAfter [ "mdns" ]) # after dns
|
2020-05-05 23:17:05 +01:00
|
|
|
]);
|
2009-10-12 17:36:19 +01:00
|
|
|
|
2015-12-21 16:28:44 +00:00
|
|
|
environment.systemPackages = [ pkgs.avahi ];
|
2009-10-12 17:36:19 +01:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
environment.etc = (mapAttrs' (n: v: nameValuePair
|
|
|
|
"avahi/services/${n}.service"
|
|
|
|
{ ${if types.path.check v then "source" else "text"} = v; }
|
|
|
|
) cfg.extraServiceFiles);
|
2016-10-15 21:30:50 +01:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
systemd.sockets.avahi-daemon = {
|
|
|
|
description = "Avahi mDNS/DNS-SD Stack Activation Socket";
|
|
|
|
listenStreams = [ "/run/avahi-daemon/socket" ];
|
|
|
|
wantedBy = [ "sockets.target" ];
|
|
|
|
};
|
2016-10-15 21:30:50 +01:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
systemd.tmpfiles.rules = [ "d /run/avahi-daemon - avahi avahi -" ];
|
2009-10-12 17:36:19 +01:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
systemd.services.avahi-daemon = {
|
|
|
|
description = "Avahi mDNS/DNS-SD Stack";
|
|
|
|
wantedBy = [ "multi-user.target" ];
|
|
|
|
requires = [ "avahi-daemon.socket" ];
|
2015-12-21 16:28:44 +00:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
# Make NSS modules visible so that `avahi_nss_support ()' can
|
|
|
|
# return a sensible value.
|
|
|
|
environment.LD_LIBRARY_PATH = config.system.nssModules.path;
|
2009-10-12 17:36:19 +01:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
path = [ pkgs.coreutils pkgs.avahi ];
|
2009-10-12 17:36:19 +01:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
serviceConfig = {
|
|
|
|
NotifyAccess = "main";
|
|
|
|
BusName = "org.freedesktop.Avahi";
|
|
|
|
Type = "dbus";
|
|
|
|
ExecStart = "${pkgs.avahi}/sbin/avahi-daemon --syslog -f ${avahiDaemonConf}";
|
2009-10-12 17:36:19 +01:00
|
|
|
};
|
2019-05-22 19:59:34 +01:00
|
|
|
};
|
2009-10-12 17:36:19 +01:00
|
|
|
|
|
|
|
services.dbus.enable = true;
|
2015-12-21 16:28:44 +00:00
|
|
|
services.dbus.packages = [ pkgs.avahi ];
|
2009-10-12 17:36:19 +01:00
|
|
|
|
2019-05-22 19:59:34 +01:00
|
|
|
networking.firewall.allowedUDPPorts = mkIf cfg.openFirewall [ 5353 ];
|
2008-11-23 01:28:58 +00:00
|
|
|
};
|
2008-11-23 01:29:25 +00:00
|
|
|
}
|