nixbot

builds

failed treefmt-check checks.x86_64-linux.treefmt · build #164 · raw

1treefmt v2.5.0traversed 580 files2emitted 384 files for processing3formatted 384 files (7 changed) in 859ms4 M modules/nixos/hermes/agent-config.nix5 M modules/nixos/hermes/cli.nix6 M modules/nixos/hermes/guest.nix7 M modules/nixos/hermes/host.nix8 M modules/nixos/hermes/options.nix9 M modules/nixos/hermes/simplex.nix10 M tests/hermes.nix11diff --git a/modules/nixos/hermes/agent-config.nix b/modules/nixos/hermes/agent-config.nix12index 417f808..1b03671 10064413--- a/modules/nixos/hermes/agent-config.nix14+++ b/modules/nixos/hermes/agent-config.nix15@@ -148,16 +148,15 @@ rec {16 # is the venv ROOT, not its bin dir.17 # Callers append config.nix.package when the user has config repos;18 # this file has no `config`.19- path =20- [21- "${stateDir}/.venv"22- hermesPackage23- pkgs.bash24- pkgs.coreutils25- pkgs.git26- ]27- ++ basePackages28- ++ cfg.extraPackages;29+ path = [30+ "${stateDir}/.venv"31+ hermesPackage32+ pkgs.bash33+ pkgs.coreutils34+ pkgs.git35+ ]36+ ++ basePackages37+ ++ cfg.extraPackages;38 hasConfigRepos = repos.dirs != [ ];39 };40 # The config repos this user's agent edits. ./options.nix,41diff --git a/modules/nixos/hermes/cli.nix b/modules/nixos/hermes/cli.nix42index b2b5f04..5577de6 10064443--- a/modules/nixos/hermes/cli.nix44+++ b/modules/nixos/hermes/cli.nix45@@ -47,7 +47,9 @@ let46 lib.mapAttrsToList (user: ucfg: ''47 ${user})48 ADDRESS_FILE=${hlib.simplexAddressFile user}49- AGENT_UNIT=${if ucfg.native then "hermes-simplex-address-${user}" else "microvm@${hlib.vmName user}"}50+ AGENT_UNIT=${51+ if ucfg.native then "hermes-simplex-address-${user}" else "microvm@${hlib.vmName user}"52+ }53 ;;54 '') cfg.enabledUsers55 );56@@ -78,7 +80,9 @@ let57 in58 ''59 ${user})60- ${lib.concatStringsSep "\n " (lib.mapAttrsToList (n: v: "export ${n}=${lib.escapeShellArg v}") env)}61+ ${lib.concatStringsSep "\n " (62+ lib.mapAttrsToList (n: v: "export ${n}=${lib.escapeShellArg v}") env63+ )}64 export PATH=${lib.escapeShellArg (lib.makeBinPath path)}:"$PATH"65 export LD_LIBRARY_PATH=${lib.escapeShellArg rt.env.LD_LIBRARY_PATH}"''${LD_LIBRARY_PATH:+:$LD_LIBRARY_PATH}"66 ;;67diff --git a/modules/nixos/hermes/guest.nix b/modules/nixos/hermes/guest.nix68index 5378741..202a969 10064469--- a/modules/nixos/hermes/guest.nix70+++ b/modules/nixos/hermes/guest.nix71@@ -347,7 +347,7 @@ in72 stateDir = guestStateDir;73 workingDirectory = guestWorkspace user;74 addToSystemPackages = true;75- settings = ac.settings;76+ inherit (ac) settings;77 environment =78 nixAgentEnv79 // ac.simplexEnv {80@@ -361,7 +361,8 @@ in81 HERMES_SANDBOX = "microvm";82 };83 inherit (cfg) extraPlugins;84- extraPackages = basePackages ++ cfg.extraPackages ++ lib.optional nixosConfigEnabled config.nix.package;85+ extraPackages =86+ basePackages ++ cfg.extraPackages ++ lib.optional nixosConfigEnabled config.nix.package;87 mcpServers = lib.optionalAttrs ucfg.spacesGateway.enable {88 spaces = {89 command = "${pkgs.socat}/bin/socat";90diff --git a/modules/nixos/hermes/host.nix b/modules/nixos/hermes/host.nix91index 04b66e7..65731fd 10064492--- a/modules/nixos/hermes/host.nix93+++ b/modules/nixos/hermes/host.nix94@@ -310,20 +310,20 @@ in95 ))96 (forEachVmUser (97 user: ucfg: {98- "hermes-spaces-bridge-${user}" = lib.mkIf ucfg.spacesGateway.enable {99- description = "spaces bridge socket for ${vmName user}";100- wantedBy = [ "sockets.target" ];101- # "vsock::<port>" binds VMADDR_CID_ANY on the host.102- listenStreams = [ "vsock::${toString (spacesVsockPort user)}" ];103- socketConfig.Accept = true;104- # Any guest can complete a vsock connect. The helper rejects it105- # post-accept. So a hostile sibling microVM could trip the106- # Accept=yes trigger limit. That limit is 200 per 2s. Then it107- # could fail the socket. This is a cross-VM DoS. Rejected108- # instances exit within milliseconds. MaxConnections bounds the109- # buildup.110- socketConfig.TriggerLimitIntervalSec = 0;111- };112+ "hermes-spaces-bridge-${user}" = lib.mkIf ucfg.spacesGateway.enable {113+ description = "spaces bridge socket for ${vmName user}";114+ wantedBy = [ "sockets.target" ];115+ # "vsock::<port>" binds VMADDR_CID_ANY on the host.116+ listenStreams = [ "vsock::${toString (spacesVsockPort user)}" ];117+ socketConfig.Accept = true;118+ # Any guest can complete a vsock connect. The helper rejects it119+ # post-accept. So a hostile sibling microVM could trip the120+ # Accept=yes trigger limit. That limit is 200 per 2s. Then it121+ # could fail the socket. This is a cross-VM DoS. Rejected122+ # instances exit within milliseconds. MaxConnections bounds the123+ # buildup.124+ socketConfig.TriggerLimitIntervalSec = 0;125+ };126 }127 ))128 ];129diff --git a/modules/nixos/hermes/options.nix b/modules/nixos/hermes/options.nix130index 58a1db3..e5d55e1 100644131--- a/modules/nixos/hermes/options.nix132+++ b/modules/nixos/hermes/options.nix133@@ -592,9 +592,7 @@ in134 # this covers the MAC too.135 map (fn: {136 assertion =137- !ucfg.enable138- || ucfg.native139- || lib.count (u: hlib.${fn} u == hlib.${fn} user) vsockUsers == 1;140+ !ucfg.enable || ucfg.native || lib.count (u: hlib.${fn} u == hlib.${fn} user) vsockUsers == 1;141 message = "services.hermes-microvm: ${fn} collision on ${user} — rename one of the colliding users or disable one VM (services.hermes-microvm.users.<name>.enable = false).";142 }) [ "cidFor" ]143 ) cfg.users144@@ -633,7 +631,9 @@ in145 ++ lib.mapAttrsToList (user: ucfg: {146 assertion =147 !(ucfg.enable && ucfg.native)148- || lib.count (u: u.enable && u.native && u.simplexPort == ucfg.simplexPort) (lib.attrValues cfg.users) == 1;149+ ||150+ lib.count (u: u.enable && u.native && u.simplexPort == ucfg.simplexPort) (lib.attrValues cfg.users)151+ == 1;152 message = "services.hermes-microvm: duplicate simplexPort ${toString ucfg.simplexPort} (${user}) — the hash-derived default collided in its 1000-port window; set services.hermes-microvm.users.<name>.simplexPort explicitly on one of them.";153 }) cfg.users;154 };155diff --git a/modules/nixos/hermes/simplex.nix b/modules/nixos/hermes/simplex.nix156index fa8139c..7aac29d 100644157--- a/modules/nixos/hermes/simplex.nix158+++ b/modules/nixos/hermes/simplex.nix159@@ -78,7 +78,10 @@ in160 RestartSec = 5;161 # No prompts: a display-name or migration prompt leaves the unit dead.162 ExecStart =163- if bindPort == null then "${startScript}" else "${daemonArgs} --chat-server-port ${toString bindPort}";164+ if bindPort == null then165+ "${startScript}"166+ else167+ "${daemonArgs} --chat-server-port ${toString bindPort}";168 };169 };170 171diff --git a/tests/hermes.nix b/tests/hermes.nix172index ed7ca7e..77daf78 100644173--- a/tests/hermes.nix174+++ b/tests/hermes.nix175@@ -1532,7 +1532,8 @@ in176 # LoadCredential resolves before the unit's own ExecStartPre, so the177 # dashboard unit must not mint its own token; the agent does.178 agentMintsToken = lib.any (lib.hasInfix "hermes-desktop-token-bob") nativeAgent.serviceConfig.ExecStartPre;179- dashboardMintsNone = !lib.any (lib.hasInfix "hermes-desktop-token") nativeDashboard.serviceConfig.ExecStartPre;180+ dashboardMintsNone =181+ !lib.any (lib.hasInfix "hermes-desktop-token") nativeDashboard.serviceConfig.ExecStartPre;182 afterAgent = lib.elem "hermes-agent-bob.service" nativeDashboard.after;183 wantsAgent = lib.elem "hermes-agent-bob.service" nativeDashboard.wants;184 };185@@ -1552,7 +1553,12 @@ in186 testAgentEnv = {187 expr = {188 inherit (nativeAgent.environment) HOME HERMES_HOME HERMES_SANDBOX;189- inherit (nativeAgent.serviceConfig) User Group WorkingDirectory LoadCredential;190+ inherit (nativeAgent.serviceConfig)191+ User192+ Group193+ WorkingDirectory194+ LoadCredential195+ ;196 gateway = lib.hasSuffix "/bin/hermes gateway" nativeAgent.serviceConfig.ExecStart;197 seedsModel = lib.hasInfix ".model-seeded" nativeSeedAgent.preStart;198 noSeedWithoutModel = lib.hasInfix ".model-seeded" nativeAgent.preStart;199@@ -1590,7 +1596,8 @@ in200 # directly; the uid resolves at run time.201 testSpacesMcp = {202 expr = {203- bob = lib.hasInfix "\"mcp_servers\":{\"spaces\":{\"args\":[],\"command\":\"/nix/store/" nativeSys.services.hermes-microvm.nativeSettingsFiles.bob.text204+ bob =205+ lib.hasInfix "\"mcp_servers\":{\"spaces\":{\"args\":[],\"command\":\"/nix/store/" nativeSys.services.hermes-microvm.nativeSettingsFiles.bob.text206 && lib.hasInfix "-hermes-spaces-mcp\"" nativeSys.services.hermes-microvm.nativeSettingsFiles.bob.text;207 noVsock = lib.hasInfix "VSOCK" nativeSys.services.hermes-microvm.nativeSettingsFiles.bob.text;208 aliceHasNone = nativeSys.services.hermes-microvm.nativeSettingsFiles ? alice;209@@ -1643,7 +1650,7 @@ in210 testShim = {211 expr =212 let213- text = (hermesShimOf nativeSys).text;214+ inherit ((hermesShimOf nativeSys)) text;215 in216 {217 bobNative = lib.hasInfix "bob)\n mode=native" text;218@@ -1693,13 +1700,12 @@ in219 {220 daemonBindsUid = lib.hasInfix "--chat-server-port $((10000 + $(" nativeSimplex.startScript.text;221 bobUsesIt = lib.hasInfix "hermes-simplex-start" (svc "hermes-simplex-bob").serviceConfig.ExecStart;222- aliceUsesIt = lib.hasInfix "hermes-simplex-start" (svc "hermes-simplex-alice").serviceConfig.ExecStart;223- bobAgentDialsPublic =224- lib.hasInfix "SIMPLEX_WS_URL=ws://127.0.0.1:${toString (hlib.simplexPortFor "bob")}"225- (svc "hermes-agent-bob").preStart;226- aliceAgentDialsPublic =227- lib.hasInfix "SIMPLEX_WS_URL=ws://127.0.0.1:${toString (hlib.simplexPortFor "alice")}"228- (svc "hermes-agent-alice").preStart;229+ aliceUsesIt = lib.hasInfix "hermes-simplex-start" (svc "hermes-simplex-alice")230+ .serviceConfig.ExecStart;231+ bobAgentDialsPublic = lib.hasInfix "SIMPLEX_WS_URL=ws://127.0.0.1:${toString (hlib.simplexPortFor "bob")}" (svc "hermes-agent-bob")232+ .preStart;233+ aliceAgentDialsPublic = lib.hasInfix "SIMPLEX_WS_URL=ws://127.0.0.1:${toString (hlib.simplexPortFor "alice")}" (svc "hermes-agent-alice")234+ .preStart;235 addressDialsPublic = (svc "hermes-simplex-address-bob").environment.SIMPLEX_WS_URL;236 distinct = hlib.simplexPortFor "alice" != hlib.simplexPortFor "bob";237 quiet = failedAssertions twoNative;238@@ -1756,8 +1762,11 @@ in239 expr = {240 nativeRefusesVm = lib.any (lib.hasInfix "hermes-native-guard-bob") nativeAgent.serviceConfig.ExecStartPre;241 dashboardToo = lib.any (lib.hasInfix "hermes-native-guard-bob") nativeDashboard.serviceConfig.ExecStartPre;242- vmRefusesNative = lib.any (lib.hasInfix "hermes-vm-guard-alice") nativeSys.systemd.services."microvm-virtiofsd@hermes-alice".serviceConfig.ExecStartPre;243- afterFirewall = lib.elem "hermes-firewall.service" nativeDashboard.after244+ vmRefusesNative =245+ lib.any (lib.hasInfix "hermes-vm-guard-alice")246+ nativeSys.systemd.services."microvm-virtiofsd@hermes-alice".serviceConfig.ExecStartPre;247+ afterFirewall =248+ lib.elem "hermes-firewall.service" nativeDashboard.after249 && lib.elem "hermes-firewall.service" nativeSys.systemd.services."hermes-simplex-bob".after;250 };251 expected = {