refactor: extract bitcoin stack into Sovran_Bitcoin flake input
Decouple the Bitcoin/Lightning modules and packages into the standalone
Sovran_Bitcoin flake, consumed as a NixOS module input.
Deleted (now in Sovran_Bitcoin):
- modules/bitcoin/ (19 files — vendored nix-bitcoin modules)
- modules/bitcoinecosystem.nix
- modules/nwc-wallets.nix
- modules/mempool.nix
- packages/{albyhub,mempool,rtl,build-support}/
- tests/bitcoin-btcpay-hardening.nix
Created:
- modules/sovran-bitcoin-integration.nix — the OS-specific bridge that
maps sovran_systemsOS.* options to sovran-bitcoin.* and applies
Second_Drive paths, operator 'free', forced wallet, firewall 3051,
and Sovran Hub NWC environment wiring.
Modified:
- flake.nix — added sovran-bitcoin flake input, updated module imports
- modules/modules.nix — removed deleted imports
- modules/core/sovran-hub.nix — version metadata now reads from
pkgs.sovran-bitcoin.* overlay instead of local packages/
- tests/test_bitcoin_tor_gossip.py — updated to check integration layer
The sovran_systemsOS.* option namespace is preserved. The Hub, roles,
and custom.nix continue to work unchanged.
This commit is contained in:
@@ -333,33 +333,6 @@ class TestSshPubkeyValidation(unittest.TestCase):
|
||||
_validate_ssh_pubkey("ssh-ed25519")
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# LND macaroon command-line safety
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
class TestLndMacaroonCommandLineSafety(unittest.TestCase):
|
||||
"""The LND admin macaroon must never be exposed in curl's argv."""
|
||||
|
||||
@classmethod
|
||||
def setUpClass(cls):
|
||||
path = os.path.join(_REPO_ROOT, "modules", "bitcoin", "lnd.nix")
|
||||
with open(path, encoding="utf-8") as f:
|
||||
cls.lnd_module = f.read()
|
||||
|
||||
def test_admin_macaroon_not_interpolated_into_header_argument(self):
|
||||
self.assertNotIn(
|
||||
'-H "Grpc-Metadata-macaroon: $(',
|
||||
self.lnd_module,
|
||||
)
|
||||
|
||||
def test_admin_macaroon_header_is_passed_via_file_descriptor(self):
|
||||
self.assertIn("adminMacaroonHex=$(", self.lnd_module)
|
||||
self.assertIn(
|
||||
"""-H @<(printf 'Grpc-Metadata-macaroon: %s\\n' "$adminMacaroonHex")""",
|
||||
self.lnd_module,
|
||||
)
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Auth-exempt paths
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
Reference in New Issue
Block a user