diff --git a/modules/bitcoind.nix b/modules/bitcoind.nix index 36ef911..26d46c7 100644 --- a/modules/bitcoind.nix +++ b/modules/bitcoind.nix @@ -289,7 +289,7 @@ let nbLib = config.nix-bitcoin.lib; secretsDir = config.nix-bitcoin.secretsDir; - i2pSAM = config.services.i2pd.proto.sam; + i2pSAM = config.services.i2pd.settings.sam; configFile = builtins.toFile "bitcoin.conf" '' # We're already logging via journald @@ -379,7 +379,13 @@ in { services.i2pd = mkIf (cfg.i2p != false) { enable = true; - proto.sam.enable = true; + # `settings` is freeform and has no defaults; restate the endpoint the + # old `proto.sam` option provided (127.0.0.1:7656). See netns-isolation. + settings.sam = { + enabled = true; + address = mkDefault "127.0.0.1"; + port = mkDefault 7656; + }; }; systemd.tmpfiles.rules = [ diff --git a/modules/netns-isolation.nix b/modules/netns-isolation.nix index 9357503..307fef2 100644 --- a/modules/netns-isolation.nix +++ b/modules/netns-isolation.nix @@ -111,10 +111,17 @@ in { port = 9050; IsolateDestAddr = true; }; - services.i2pd.proto.sam.address = bridgeIp; + # nixpkgs 26.11 replaced `services.i2pd.proto.*` with the freeform + # `services.i2pd.settings.*`, which carries no defaults. The old + # `proto.sam` endpoint defaulted to 127.0.0.1:7656, and we read the port + # back below, so the default has to be restated here. + services.i2pd.settings.sam = { + address = bridgeIp; + port = mkDefault 7656; + }; networking.firewall.interfaces.nb-br.allowedTCPPorts = [ config.services.tor.client.socksListenAddress.port - config.services.i2pd.proto.sam.port + config.services.i2pd.settings.sam.port ]; boot.kernel.sysctl."net.ipv4.ip_forward" = true;