[arch-commits] Commit in dnscrypt-proxy/repos (5 files)

David Runge dvzrv at gemini.archlinux.org
Wed Feb 16 08:33:00 UTC 2022


    Date: Wednesday, February 16, 2022 @ 08:33:00
  Author: dvzrv
Revision: 1133435

archrelease: copy trunk to community-testing-x86_64

Added:
  dnscrypt-proxy/repos/community-testing-x86_64/
  dnscrypt-proxy/repos/community-testing-x86_64/PKGBUILD
    (from rev 1133434, dnscrypt-proxy/trunk/PKGBUILD)
  dnscrypt-proxy/repos/community-testing-x86_64/dnscrypt-proxy.install
    (from rev 1133434, dnscrypt-proxy/trunk/dnscrypt-proxy.install)
  dnscrypt-proxy/repos/community-testing-x86_64/dnscrypt-proxy.service
    (from rev 1133434, dnscrypt-proxy/trunk/dnscrypt-proxy.service)
  dnscrypt-proxy/repos/community-testing-x86_64/dnscrypt-proxy.socket
    (from rev 1133434, dnscrypt-proxy/trunk/dnscrypt-proxy.socket)

------------------------+
 PKGBUILD               |   74 +++++++++++++++++++++++++++++++++++++++++++++++
 dnscrypt-proxy.install |    9 +++++
 dnscrypt-proxy.service |   37 +++++++++++++++++++++++
 dnscrypt-proxy.socket  |   16 ++++++++++
 4 files changed, 136 insertions(+)

Copied: dnscrypt-proxy/repos/community-testing-x86_64/PKGBUILD (from rev 1133434, dnscrypt-proxy/trunk/PKGBUILD)
===================================================================
--- community-testing-x86_64/PKGBUILD	                        (rev 0)
+++ community-testing-x86_64/PKGBUILD	2022-02-16 08:33:00 UTC (rev 1133435)
@@ -0,0 +1,74 @@
+# Maintainer: David Runge <dvzrv at archlinux.org>
+# Contributor: Felix Yan <felixonmars at archlinux.org>
+# Contributor: Techlive Zheng <techlivezheng at gmail dot com>
+# Contributor: peace4all <markspost at rocketmail dot com>
+
+pkgname=dnscrypt-proxy
+pkgver=2.1.1
+pkgrel=2
+pkgdesc="A flexible DNS proxy, with support for encrypted DNS protocols"
+arch=(x86_64)
+url="https://github.com/DNSCrypt/dnscrypt-proxy"
+license=(ISC)
+depends=(glibc)
+makedepends=(git go)
+optdepends=('python-urllib3: for generate-domains-blocklist')
+install=$pkgname.install
+backup=(
+  etc/$pkgname/${pkgname}.toml
+  etc/$pkgname/allowed-ips.txt
+  etc/$pkgname/allowed-names.txt
+  etc/$pkgname/blocked-ips.txt
+  etc/$pkgname/blocked-names.txt
+  etc/$pkgname/cloaking-rules.txt
+  etc/$pkgname/forwarding-rules.txt
+)
+source=(
+  git+https://github.com/dnscrypt/$pkgname#tag=$pkgver?signed
+  $pkgname.service
+  $pkgname.socket
+  $pkgname-$pkgver-configuration.patch::https://github.com/dvzrv/dnscrypt-proxy/commit/c3b021adcfc564f331ba531c35b4501adfee53d3.patch
+)
+sha512sums=('SKIP'
+            '5589eddf9d5fda86778ebc91c9e20d8acfdcf86bc1f1a5d34279f33c402f32dc73539c0c0ba6bd74b80617e9abcc49c8c68cc06f171f74c66f2ffc92dfeecd75'
+            '56a56e87032da9316b392b0613124b0743673041596c717005541ae9b3994c7fc16c02497ea773d321f45d8e0f9ea8fda00783062cef4d5c8277b5b6f7cb10d5'
+            '5153386b92ff3540c9e564fa9224a7300e31fe9d0e0a0dd1a262c389e8d115eac549cb863e822c727de52a28d8f2a7a31188d4c793899ae42809f55a0e299b63')
+validpgpkeys=('54A2B8892CC3D6A597B92B6C210627AABA709FE1') # Frank Denis (Jedi/Sector One) <pgp at pureftpd.org
+
+prepare() {
+  cd $pkgname
+  patch -Np1 -i ../$pkgname-$pkgver-configuration.patch
+}
+
+build() {
+  cd $pkgname/$pkgname
+  export CGO_CPPFLAGS="$CPPFLAGS"
+  export CGO_CFLAGS="$CFLAGS"
+  export CGO_CXXFLAGS="$CXXFLAGS"
+  export CGO_LDFLAGS="$LDFLAGS"
+  export GOFLAGS="-buildmode=pie -trimpath -ldflags=-linkmode=external -mod=readonly -modcacherw"
+  go build
+}
+
+package() {
+  local _config
+
+  cd $pkgname
+  # executable
+  install -vDm 755 $pkgname/$pkgname -t "$pkgdir/usr/bin/"
+  # config files
+  install -vDm 644 $pkgname/example-$pkgname.toml "$pkgdir/etc/$pkgname/$pkgname.toml"
+  for _config in {{allowed,blocked}-{ips,names},{cloaking,forwarding}-rules,captive-portals}.txt; do
+    install -vDm 644 "$pkgname/example-$_config" "$pkgdir/etc/$pkgname/$_config"
+  done
+  # utils
+  install -vDm 644 utils/generate-domains-blocklist/*.{conf,txt} -t "$pkgdir/usr/share/$pkgname/utils/generate-domains-blocklist"
+  install -vDm 755 utils/generate-domains-blocklist/generate-domains-blocklist.py "$pkgdir/usr/bin/generate-domains-blocklist"
+  # systemd service/socket
+  install -vDm 644 ../$pkgname.{service,socket} -t "$pkgdir/usr/lib/systemd/system/"
+  # license
+  install -vDm 644 LICENSE -t "$pkgdir/usr/share/licenses/$pkgname"
+  # docs
+  install -vDm 644 {ChangeLog,README.md} -t "$pkgdir/usr/share/doc/$pkgname"
+}
+# vim:set ts=2 sw=2 et:

Copied: dnscrypt-proxy/repos/community-testing-x86_64/dnscrypt-proxy.install (from rev 1133434, dnscrypt-proxy/trunk/dnscrypt-proxy.install)
===================================================================
--- community-testing-x86_64/dnscrypt-proxy.install	                        (rev 0)
+++ community-testing-x86_64/dnscrypt-proxy.install	2022-02-16 08:33:00 UTC (rev 1133435)
@@ -0,0 +1,9 @@
+post_upgrade() {
+  if [ "$(vercmp "$2" '1.9.5-1')" -le 0 ]; then
+    echo 'The configuration file(s) and setup of dnscrypt-proxy has changed considerably since version 1.x.'
+    echo 'Please refer to the new upstream information for help!'
+  fi
+  if [ "$(vercmp "$2" '2.0.45-1')" -le 0 ]; then
+    echo 'Some of the configuration files have been renamed. Read /usr/share/doc/dnscrypt-proxy/ChangeLog to merge files accordingly.'
+  fi
+}

Copied: dnscrypt-proxy/repos/community-testing-x86_64/dnscrypt-proxy.service (from rev 1133434, dnscrypt-proxy/trunk/dnscrypt-proxy.service)
===================================================================
--- community-testing-x86_64/dnscrypt-proxy.service	                        (rev 0)
+++ community-testing-x86_64/dnscrypt-proxy.service	2022-02-16 08:33:00 UTC (rev 1133435)
@@ -0,0 +1,37 @@
+[Unit]
+Description=DNSCrypt-proxy client
+Documentation=https://github.com/jedisct1/dnscrypt-proxy/wiki
+Wants=network-online.target nss-lookup.target
+Before=nss-lookup.target
+
+[Service]
+AmbientCapabilities=CAP_NET_BIND_SERVICE
+CacheDirectory=dnscrypt-proxy
+CapabilityBoundingSet=CAP_NET_BIND_SERVICE
+DynamicUser=yes
+ExecStart=/usr/bin/dnscrypt-proxy --config /etc/dnscrypt-proxy/dnscrypt-proxy.toml
+LockPersonality=yes
+LogsDirectory=dnscrypt-proxy
+MemoryDenyWriteExecute=true
+NonBlocking=true
+NoNewPrivileges=true
+PrivateDevices=true
+ProtectControlGroups=yes
+ProtectHome=yes
+ProtectHostname=yes
+ProtectKernelLogs=yes
+ProtectKernelModules=yes
+ProtectKernelTunables=yes
+ProtectSystem=strict
+RestrictAddressFamilies=AF_INET AF_INET6
+RestrictNamespaces=true
+RestrictRealtime=true
+RuntimeDirectory=dnscrypt-proxy
+StateDirectory=dnscrypt-proxy
+SystemCallArchitectures=native
+SystemCallFilter=@system-service
+SystemCallFilter=~@resources @privileged
+SystemCallFilter=@chown
+
+[Install]
+WantedBy=multi-user.target

Copied: dnscrypt-proxy/repos/community-testing-x86_64/dnscrypt-proxy.socket (from rev 1133434, dnscrypt-proxy/trunk/dnscrypt-proxy.socket)
===================================================================
--- community-testing-x86_64/dnscrypt-proxy.socket	                        (rev 0)
+++ community-testing-x86_64/dnscrypt-proxy.socket	2022-02-16 08:33:00 UTC (rev 1133435)
@@ -0,0 +1,16 @@
+[Unit]
+Description=DNSCrypt-proxy socket
+Documentation=https://github.com/jedisct1/dnscrypt-proxy/wiki
+Before=nss-lookup.target
+Wants=nss-lookup.target network-online.target
+
+[Socket]
+ListenStream=127.0.0.1:53
+ListenDatagram=127.0.0.1:53
+ListenStream=[::1]:53
+ListenDatagram=[::1]:53
+NoDelay=true
+DeferAcceptSec=1
+
+[Install]
+WantedBy=sockets.target



More information about the arch-commits mailing list