mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-11 22:37:25 +03:00
fix(vds-nftables): remove allowPing — not a top-level networking option
networking.allowPing was a top-level networking option when firewall.enable = true. With firewall.enable = false (T3 Option A), the option no longer exists at the networking level. ICMP is now handled by the nftables ruleset directly (). Rebuild error: 'The option networking.allowPing does not exist. Definition values: networking.domain, networking.vlans, networking.wicd.' Fix: remove the line. No behavior change — ICMP is still accepted via nftables.
This commit is contained in:
@@ -89,7 +89,10 @@
|
||||
firewall.enable = false;
|
||||
firewall.allowedTCPPorts = lib.mkForce [ ];
|
||||
firewall.interfaces = lib.mkForce { };
|
||||
allowPing = true;
|
||||
# allowPing removed 2026-10-10 (T3 Option A): with firewall.enable = false,
|
||||
# `networking.allowPing` no longer exists as a top-level option. ICMP
|
||||
# accept is now handled by the nftables ruleset below
|
||||
# (`ip protocol icmp accept`).
|
||||
nftables = {
|
||||
enable = true;
|
||||
ruleset = ''
|
||||
|
||||
Reference in New Issue
Block a user