From 3deaa75f5cae6f8a07cc5fce6637191b33f7b61e Mon Sep 17 00:00:00 2001 From: oqyude Date: Sat, 10 Oct 2026 16:47:02 +0300 Subject: [PATCH] =?UTF-8?q?fix(vds-nftables):=20remove=20allowPing=20?= =?UTF-8?q?=E2=80=94=20not=20a=20top-level=20networking=20option?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit networking.allowPing was a top-level networking option when firewall.enable = true. With firewall.enable = false (T3 Option A), the option no longer exists at the networking level. ICMP is now handled by the nftables ruleset directly (). Rebuild error: 'The option networking.allowPing does not exist. Definition values: networking.domain, networking.vlans, networking.wicd.' Fix: remove the line. No behavior change — ICMP is still accepted via nftables. --- configurations/vds.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/configurations/vds.nix b/configurations/vds.nix index 46fd5bf..fe7cac6 100644 --- a/configurations/vds.nix +++ b/configurations/vds.nix @@ -89,7 +89,10 @@ firewall.enable = false; firewall.allowedTCPPorts = lib.mkForce [ ]; firewall.interfaces = lib.mkForce { }; - allowPing = true; + # allowPing removed 2026-10-10 (T3 Option A): with firewall.enable = false, + # `networking.allowPing` no longer exists as a top-level option. ICMP + # accept is now handled by the nftables ruleset below + # (`ip protocol icmp accept`). nftables = { enable = true; ruleset = ''