From 9b3acfd5bc6de89b072f9c6a031e45b0ef52ae9f Mon Sep 17 00:00:00 2001 From: TheCodeLamp <12064217+TheCodeLamp@users.noreply.github.com> Date: Wed, 16 Sep 2026 23:15:17 +0200 Subject: [PATCH 1/7] Add `protonvpn` --- build_scripts/install-base.sh | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/build_scripts/install-base.sh b/build_scripts/install-base.sh index 1a02c3f..5f4a34b 100755 --- a/build_scripts/install-base.sh +++ b/build_scripts/install-base.sh @@ -91,3 +91,8 @@ WantedBy=multi-user.target EOF systemctl enable nix.mount echo "::endgroup::" + +# =================== PROTONVPN ==================== +echo "::group:: Build Base - Nix Package Manager" +dnf install --assumeyes protonvpn-cli +echo "::endgroup::" From e734f6cfa552fc7a9b6b0e93660ed9c3de42dc5c Mon Sep 17 00:00:00 2001 From: TheCodeLamp <12064217+TheCodeLamp@users.noreply.github.com> Date: Wed, 16 Sep 2026 23:20:04 +0200 Subject: [PATCH 2/7] Fix group name --- build_scripts/install-base.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/build_scripts/install-base.sh b/build_scripts/install-base.sh index 5f4a34b..538563e 100755 --- a/build_scripts/install-base.sh +++ b/build_scripts/install-base.sh @@ -93,6 +93,6 @@ systemctl enable nix.mount echo "::endgroup::" # =================== PROTONVPN ==================== -echo "::group:: Build Base - Nix Package Manager" +echo "::group:: Build Base - Proton VPN" dnf install --assumeyes protonvpn-cli echo "::endgroup::" From 96b2fe385ed66f37e89ad6874d6d20b5143341f4 Mon Sep 17 00:00:00 2001 From: TheCodeLamp <12064217+TheCodeLamp@users.noreply.github.com> Date: Thu, 17 Sep 2026 00:06:36 +0200 Subject: [PATCH 3/7] Download from official proton repo --- build_scripts/install-base.sh | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/build_scripts/install-base.sh b/build_scripts/install-base.sh index 538563e..8f668c9 100755 --- a/build_scripts/install-base.sh +++ b/build_scripts/install-base.sh @@ -94,5 +94,10 @@ echo "::endgroup::" # =================== PROTONVPN ==================== echo "::group:: Build Base - Proton VPN" -dnf install --assumeyes protonvpn-cli +PROTON_VERSION=1.0.4 +PROTONVPN_FILE=/tmp/protonvpn-release.rpm +curl -fsSL "https://repo.protonvpn.com/fedora-$(rpm -E %fedora)-stable/protonvpn-stable-release/protonvpn-stable-release-${PROTONVPN_VERSION}-1.noarch.rpm" -o ${PROTONVPN_FILE} +dnf install --assumeyes ${PROTONVPN_FILE} +dnf install --assumeyes proton-vpn-cli +rm ${PROTONVPN_FILE} echo "::endgroup::" From f80a4f841eef2be3cb559a0e399658125153006c Mon Sep 17 00:00:00 2001 From: TheCodeLamp <12064217+TheCodeLamp@users.noreply.github.com> Date: Thu, 17 Sep 2026 00:10:10 +0200 Subject: [PATCH 4/7] Use renovate to update protonvpn version --- build_scripts/install-base.sh | 2 +- renovate.json | 9 +++++++++ 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/build_scripts/install-base.sh b/build_scripts/install-base.sh index 8f668c9..0fb99b6 100755 --- a/build_scripts/install-base.sh +++ b/build_scripts/install-base.sh @@ -94,7 +94,7 @@ echo "::endgroup::" # =================== PROTONVPN ==================== echo "::group:: Build Base - Proton VPN" -PROTON_VERSION=1.0.4 +PROTON_VERSION="1.0.4" PROTONVPN_FILE=/tmp/protonvpn-release.rpm curl -fsSL "https://repo.protonvpn.com/fedora-$(rpm -E %fedora)-stable/protonvpn-stable-release/protonvpn-stable-release-${PROTONVPN_VERSION}-1.noarch.rpm" -o ${PROTONVPN_FILE} dnf install --assumeyes ${PROTONVPN_FILE} diff --git a/renovate.json b/renovate.json index feeebdc..4c28442 100644 --- a/renovate.json +++ b/renovate.json @@ -16,6 +16,15 @@ "matchStrings": ["CHUNKAH_VERSION=\"(?.*?)\""], "depNameTemplate": "coreos/chunkah", "datasourceTemplate": "github-releases" + }, + { + "customType": "regex", + "managerFilePatterns": ["build_scripts/install-base.sh"], + "matchStrings": ["PROTONVPN_VERSION=\"(?.*?)\""], + "datasourceTemplate": "github-tags", + "depNameTemplate": "ProtonVPN/proton-vpn-cli", + "extractVersionTemplate": "^v(?.*)$", + "versioningTemplate": "semver" } ] } From cd5c8433ee892dec57f222175c56c80b9b9333df Mon Sep 17 00:00:00 2001 From: TheCodeLamp <12064217+TheCodeLamp@users.noreply.github.com> Date: Thu, 17 Sep 2026 00:14:07 +0200 Subject: [PATCH 5/7] Use correct var name --- build_scripts/install-base.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/build_scripts/install-base.sh b/build_scripts/install-base.sh index 0fb99b6..11c217c 100755 --- a/build_scripts/install-base.sh +++ b/build_scripts/install-base.sh @@ -94,7 +94,7 @@ echo "::endgroup::" # =================== PROTONVPN ==================== echo "::group:: Build Base - Proton VPN" -PROTON_VERSION="1.0.4" +PROTONVPN_VERSION="1.0.4" PROTONVPN_FILE=/tmp/protonvpn-release.rpm curl -fsSL "https://repo.protonvpn.com/fedora-$(rpm -E %fedora)-stable/protonvpn-stable-release/protonvpn-stable-release-${PROTONVPN_VERSION}-1.noarch.rpm" -o ${PROTONVPN_FILE} dnf install --assumeyes ${PROTONVPN_FILE} From 2e4f5f3933aab9d1c38d3e88fe2e0180c1e7f616 Mon Sep 17 00:00:00 2001 From: TheCodeLamp <12064217+TheCodeLamp@users.noreply.github.com> Date: Thu, 17 Sep 2026 14:39:33 +0200 Subject: [PATCH 6/7] Move to top --- build_scripts/install-base.sh | 20 +++++++++++--------- 1 file changed, 11 insertions(+), 9 deletions(-) diff --git a/build_scripts/install-base.sh b/build_scripts/install-base.sh index 11c217c..ea47a74 100755 --- a/build_scripts/install-base.sh +++ b/build_scripts/install-base.sh @@ -2,6 +2,17 @@ set -ouex pipefail +# =================== PROTONVPN ==================== +echo "::group:: Build Base - Proton VPN" +PROTONVPN_VERSION="1.0.4" +PROTONVPN_FILE=/tmp/protonvpn-release.rpm +curl -fsSL "https://repo.protonvpn.com/fedora-$(rpm -E %fedora)-stable/protonvpn-stable-release/protonvpn-stable-release-${PROTONVPN_VERSION}-1.noarch.rpm" -o ${PROTONVPN_FILE} +dnf install --assumeyes ${PROTONVPN_FILE} +dnf install --assumeyes proton-vpn-cli +rm ${PROTONVPN_FILE} +echo "::endgroup::" + + echo "::group:: Build Base - Misc Packages" dnf install --assumeyes \ bat \ @@ -92,12 +103,3 @@ EOF systemctl enable nix.mount echo "::endgroup::" -# =================== PROTONVPN ==================== -echo "::group:: Build Base - Proton VPN" -PROTONVPN_VERSION="1.0.4" -PROTONVPN_FILE=/tmp/protonvpn-release.rpm -curl -fsSL "https://repo.protonvpn.com/fedora-$(rpm -E %fedora)-stable/protonvpn-stable-release/protonvpn-stable-release-${PROTONVPN_VERSION}-1.noarch.rpm" -o ${PROTONVPN_FILE} -dnf install --assumeyes ${PROTONVPN_FILE} -dnf install --assumeyes proton-vpn-cli -rm ${PROTONVPN_FILE} -echo "::endgroup::" From b4f9d88b359262df6217772f7daa9a600f519238 Mon Sep 17 00:00:00 2001 From: TheCodeLamp <12064217+TheCodeLamp@users.noreply.github.com> Date: Thu, 17 Sep 2026 22:11:29 +0200 Subject: [PATCH 7/7] Progress --- build_scripts/install-base.sh | 19 +++++++++++------ pvpnd.service | 40 +++++++++++++++++++++++++++++++++++ 2 files changed, 52 insertions(+), 7 deletions(-) create mode 100644 pvpnd.service diff --git a/build_scripts/install-base.sh b/build_scripts/install-base.sh index ea47a74..b3c1500 100755 --- a/build_scripts/install-base.sh +++ b/build_scripts/install-base.sh @@ -3,13 +3,18 @@ set -ouex pipefail # =================== PROTONVPN ==================== -echo "::group:: Build Base - Proton VPN" -PROTONVPN_VERSION="1.0.4" -PROTONVPN_FILE=/tmp/protonvpn-release.rpm -curl -fsSL "https://repo.protonvpn.com/fedora-$(rpm -E %fedora)-stable/protonvpn-stable-release/protonvpn-stable-release-${PROTONVPN_VERSION}-1.noarch.rpm" -o ${PROTONVPN_FILE} -dnf install --assumeyes ${PROTONVPN_FILE} -dnf install --assumeyes proton-vpn-cli -rm ${PROTONVPN_FILE} +echo "::group:: Build Base - pvpn - Proton VPN client" +TMP=$(mktemp -d) +PRE_WD=$(pwd) +cd $TMP +PVPN_VERSION="1.0.4" +for bin in pvpn pvpnd pvpnctl; do + curl -fsSL -o "${bin}" "https://github.com/YourDoritos/pVPN/releases/download/v${PVPN_VERSION}/${bin}-linux-amd64" + install -Dm755 "${bin}" "/usr/bin/${bin}" +done +cd "${PRE_WD}" +unset TMP +unset PRE_WD echo "::endgroup::" diff --git a/pvpnd.service b/pvpnd.service new file mode 100644 index 0000000..b4d4e13 --- /dev/null +++ b/pvpnd.service @@ -0,0 +1,40 @@ +[Unit] +Description=pVPN Daemon - Proton VPN Connection Manager +After=network-online.target +Wants=network-online.target + +[Service] +Type=simple +# HOME must be set explicitly. systemd leaves $HOME unset by default, which +# made the daemon's realHome() fall back to "" and write state to +# /.config/pvpn and /.local/share/pvpn (relative to the daemon's cwd "/") +# in pre-v0.2.1 (F-4 finding). We point HOME at StateDirectory rather than +# /root so that ProtectHome=true below keeps blocking real user homes. +Environment=HOME=/var/lib/pvpn +ExecStart=/usr/bin/pvpnd +Restart=on-failure +RestartSec=5 +RuntimeDirectory=pvpn +# systemd creates /var/lib/pvpn (mode 0700, owner root) on first start and +# preserves it across restarts. This holds the daemon's config, session, +# and preboot kill switch ruleset (F-3 fix). +StateDirectory=pvpn +StateDirectoryMode=0700 + +# Network control permissions +ReadWritePaths=/run/pvpn /etc/resolv.conf /etc/pvpn /var/lib/pvpn + +# --- Conservative sandboxing --- +# These are known-safe for a WireGuard-managing root daemon. Stronger +# options (NoNewPrivileges, ProtectSystem=strict, CapabilityBoundingSet, +# RestrictAddressFamilies) are deliberately left off because they can +# break netlink / nftables / DNS manipulation on some systems and need +# per-system testing. +ProtectHome=true +PrivateTmp=true +LockPersonality=true +RestrictRealtime=true +RestrictSUIDSGID=true + +[Install] +WantedBy=multi-user.target