Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 17 additions & 0 deletions build_scripts/install-base.sh
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,22 @@

set -ouex pipefail

# =================== PROTONVPN ====================
echo "::group:: Build Base - pvpn - Proton VPN client"
TMP=$(mktemp -d)
PRE_WD=$(pwd)
cd $TMP
PVPN_VERSION="1.0.4"
for bin in pvpn pvpnd pvpnctl; do
curl -fsSL -o "${bin}" "https://github.com/YourDoritos/pVPN/releases/download/v${PVPN_VERSION}/${bin}-linux-amd64"
install -Dm755 "${bin}" "/usr/bin/${bin}"
done
cd "${PRE_WD}"
unset TMP
unset PRE_WD
echo "::endgroup::"


echo "::group:: Build Base - Misc Packages"
dnf install --assumeyes \
bat \
Expand Down Expand Up @@ -91,3 +107,4 @@ WantedBy=multi-user.target
EOF
systemctl enable nix.mount
echo "::endgroup::"

40 changes: 40 additions & 0 deletions pvpnd.service
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
[Unit]
Description=pVPN Daemon - Proton VPN Connection Manager
After=network-online.target
Wants=network-online.target

[Service]
Type=simple
# HOME must be set explicitly. systemd leaves $HOME unset by default, which
# made the daemon's realHome() fall back to "" and write state to
# /.config/pvpn and /.local/share/pvpn (relative to the daemon's cwd "/")
# in pre-v0.2.1 (F-4 finding). We point HOME at StateDirectory rather than
# /root so that ProtectHome=true below keeps blocking real user homes.
Environment=HOME=/var/lib/pvpn
ExecStart=/usr/bin/pvpnd
Restart=on-failure
RestartSec=5
RuntimeDirectory=pvpn
# systemd creates /var/lib/pvpn (mode 0700, owner root) on first start and
# preserves it across restarts. This holds the daemon's config, session,
# and preboot kill switch ruleset (F-3 fix).
StateDirectory=pvpn
StateDirectoryMode=0700

# Network control permissions
ReadWritePaths=/run/pvpn /etc/resolv.conf /etc/pvpn /var/lib/pvpn

# --- Conservative sandboxing ---
# These are known-safe for a WireGuard-managing root daemon. Stronger
# options (NoNewPrivileges, ProtectSystem=strict, CapabilityBoundingSet,
# RestrictAddressFamilies) are deliberately left off because they can
# break netlink / nftables / DNS manipulation on some systems and need
# per-system testing.
ProtectHome=true
PrivateTmp=true
LockPersonality=true
RestrictRealtime=true
RestrictSUIDSGID=true

[Install]
WantedBy=multi-user.target
9 changes: 9 additions & 0 deletions renovate.json
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,15 @@
"matchStrings": ["CHUNKAH_VERSION=\"(?<currentValue>.*?)\""],
"depNameTemplate": "coreos/chunkah",
"datasourceTemplate": "github-releases"
},
{
"customType": "regex",
"managerFilePatterns": ["build_scripts/install-base.sh"],
"matchStrings": ["PROTONVPN_VERSION=\"(?<currentValue>.*?)\""],
"datasourceTemplate": "github-tags",
"depNameTemplate": "ProtonVPN/proton-vpn-cli",
"extractVersionTemplate": "^v(?<version>.*)$",
"versioningTemplate": "semver"
}
]
}
Loading