aboutsummaryrefslogtreecommitdiffstats
path: root/modules
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar@proton.me>2026-04-13 16:22:08 +0530
committerArpit Chakladar <arpitchakladar@proton.me>2026-04-13 16:22:08 +0530
commit3292982abcfd60c75a1ef3bb1214d91e4ad144aa (patch)
tree9eef028bd7c7992a00c646f54df695e102b48f6b /modules
parentf157c61914f9a4da32b4add1920f766dbb66774c (diff)
downloadhome-manager-config-3292982abcfd60c75a1ef3bb1214d91e4ad144aa.tar.gz
home-manager-config-3292982abcfd60c75a1ef3bb1214d91e4ad144aa.zip
the vpn-connect scripts can now prevents dns leaks
Diffstat (limited to 'modules')
-rw-r--r--modules/scripts/default.nix11
-rw-r--r--modules/scripts/vpn-connect.sh34
2 files changed, 34 insertions, 11 deletions
diff --git a/modules/scripts/default.nix b/modules/scripts/default.nix
index 68b4000..c312800 100644
--- a/modules/scripts/default.nix
+++ b/modules/scripts/default.nix
@@ -35,7 +35,16 @@ in
) (mkScript "system-monitor" ./system-monitor.sh))
(lib.mkIf (config.tools.openvpn.enable && config.tools.fzf.enable) (
- mkScript "vpn-connect" ./vpn-connect.sh
+ pkgs.writeShellScriptBin "vpn-connect" ''
+ #!${if config.tools.zsh.enable then (lib.getExe config.programs.zsh.package) else "/usr/bin/env sh"}
+
+ # Inject Nix store paths as environment variables for the script to use
+ export FZF_BIN="${lib.getExe pkgs.fzf}"
+ export OPENVPN_BIN="${lib.getExe pkgs.openvpn}"
+ export RESOLVED_BIN="${pkgs.openvpn}/libexec/update-systemd-resolved"
+
+ ${builtins.readFile ./vpn-connect.sh}
+ ''
))
];
};
diff --git a/modules/scripts/vpn-connect.sh b/modules/scripts/vpn-connect.sh
index 87cfdcc..0366725 100644
--- a/modules/scripts/vpn-connect.sh
+++ b/modules/scripts/vpn-connect.sh
@@ -7,7 +7,6 @@ CACHE_FILE="$HOME/.cache/openvpn/last_connection"
# Create directories
mkdir -p "$CREDS_DIR" "$SERVERS_DIR" "$(dirname "$CACHE_FILE")"
-# Logic to force a refresh (bypass cache)
REFRESH=false
if [[ "$1" == "--refresh" || "$1" == "-r" ]]; then
REFRESH=true
@@ -16,29 +15,44 @@ fi
# Try to load from cache
if [[ "$REFRESH" == false && -f "$CACHE_FILE" ]]; then
source "$CACHE_FILE"
- # Validate cached files still exist
if [[ ! -f "$CRED" || ! -f "$SERVER" ]]; then
- echo "Cached config not found, falling back to selection..."
REFRESH=true
fi
else
REFRESH=true
fi
-# If we need a refresh, run fzf
+# Selection logic
if [[ "$REFRESH" == true ]]; then
- CRED=$(find "$CREDS_DIR" -type f | fzf --prompt="Select Credentials > ")
+ # These variables ($FZF_BIN, etc) are provided by the Nix wrapper below
+ CRED=$(find "$CREDS_DIR" -type f | "$FZF_BIN" --prompt="Select Credentials > ")
[ -z "$CRED" ] && exit 1
- SERVER=$(find "$SERVERS_DIR" -type f \( -name "*.conf" -o -name "*.ovpn" \) | fzf --prompt="Select VPN Server > ")
+ SERVER=$(find "$SERVERS_DIR" -type f \( -name "*.conf" -o -name "*.ovpn" \) | "$FZF_BIN" --prompt="Select VPN Server > ")
[ -z "$SERVER" ] && exit 1
- # Save to cache
echo "CRED=\"$CRED\"" > "$CACHE_FILE"
echo "SERVER=\"$SERVER\"" >> "$CACHE_FILE"
fi
-echo "Connecting to $SERVER using $CRED..."
+echo "Connecting to $SERVER..."
-# Execute openvpn
-sudo openvpn --config "$SERVER" --auth-user-pass "$CRED"
+# Create a temporary config file that sudo can read
+TMP_CONF=$(mktemp /tmp/vpn-config.XXXXXX)
+
+# Clean the config and save to the temp file
+sed -e '/up \/etc\/openvpn\/update-resolv-conf/d' \
+ -e '/down \/etc\/openvpn\/update-resolv-conf/d' "$SERVER" > "$TMP_CONF"
+
+# Use a trap to ensure the temp file is deleted when the script exits
+# (even if you Ctrl+C)
+trap 'rm -f "$TMP_CONF"' EXIT
+
+# Execute openvpn using the temporary file
+sudo "$OPENVPN_BIN" \
+ --config "$TMP_CONF" \
+ --auth-user-pass "$CRED" \
+ --script-security 2 \
+ --up "$RESOLVED_BIN" \
+ --down "$RESOLVED_BIN" \
+ --down-pre