commit 7e9ac3af680cbbe3fe144d28ecfaf25a53c4e0ac from: Alejandro Bernal Estrada date: Thu May 21 19:41:38 2026 UTC add: paquetes Zen Browser y Mullvad VPN + servicio Shepherd - richard/packages/zen-browser.scm: paquete binary-wrap para Zen Browser 1.12.9b; extrae tarball, parchea intérprete ELF, crea wrapper Wayland y entrada .desktop para KDE. - richard/packages/mullvad.scm: paquete binary-wrap para Mullvad VPN 2026.1; extrae .deb con ar+tar (--strip-components=2), parchea ELF de mullvad-daemon y mullvad CLI con rpath a libs del bundle. - richard/services/mullvad.scm: servicio Shepherd mullvad-daemon; arranca al boot tras 'networking', crea /var/cache/mullvad-vpn y /var/log/mullvad-vpn, reinstala el paquete al perfil del sistema. Co-Authored-By: Claude Sonnet 4.6 commit - 4816a226e326620faa3242fb0292c0944d8e188d commit + 7e9ac3af680cbbe3fe144d28ecfaf25a53c4e0ac blob - e69de29bb2d1d6434b8b29ae775ad8c2e48c5391 blob + 0504e3209093219c69b471406d3edc4a508ee657 --- richard/packages/mullvad.scm +++ richard/packages/mullvad.scm @@ -0,0 +1,102 @@ +;; richard/packages/mullvad.scm +;; +;; Paquete Mullvad VPN para canal Guix personal. +;; Estrategia: binary wrap — extrae el .deb oficial, parchea los +;; binarios ELF con patchelf y ajusta el rpath a las libs del bundle. +;; +;; Para actualizar a una versión nueva: +;; 1. Cambia 'version' al nuevo tag (ej. "2026.2") +;; 2. Descarga el .deb y obtén el hash: +;; wget https://github.com/mullvad/mullvadvpn-app/releases/download/VERSION/MullvadVPN-VERSION_amd64.deb +;; sha256sum MullvadVPN-VERSION_amd64.deb | python3 -c " +;; import sys; h=input().split()[0] +;; NIX='0123456789abcdfghijklmnpqrsvwxyz' +;; d=bytes.fromhex(h); n=(len(d)*8+4)//5 +;; print(''.join(NIX[(int.from_bytes(d[b//8:b//8+2],'big')>>(11-b%8))&31] for b in [i*5 for i in range(n-1,-1,-1)]))" +;; 3. Reemplaza el (base32 "...") con el resultado + +(define-module (richard packages mullvad) + #:use-module (guix packages) + #:use-module (guix download) + #:use-module (guix build-system trivial) + #:use-module (guix gexp) + #:use-module ((guix licenses) #:prefix license:) + #:use-module (gnu packages base) ; glibc, tar + #:use-module (gnu packages compression) ; xz + #:use-module (gnu packages elf) ; patchelf + #:use-module (gnu packages commencement) ; binutils-final (ar) + #:export (mullvad-vpn)) + +(define-public mullvad-vpn + (package + (name "mullvad-vpn") + (version "2026.1") + + ;; ── Fuente: paquete .deb oficial de GitHub releases ───────────── + (source + (origin + (method url-fetch) + (uri (string-append + "https://github.com/mullvad/mullvadvpn-app/releases/download/" + version "/MullvadVPN-" version "_amd64.deb")) + (sha256 + (base32 + "0gpg5yb1b4fw6zw06ymgicw46v7qj4sf7i5zd5srdhqvn66rlmqy")))) + + (build-system trivial-build-system) + + (native-inputs + (list tar xz patchelf binutils-final)) + + (inputs + (list glibc)) + + (arguments + (list + #:modules '((guix build utils)) + #:builder + #~(begin + (use-modules (guix build utils)) + + (define out #$output) + (define tmp "/tmp/mullvad-work") + + ;; 1. Extraer data.tar.xz del .deb (formato ar) + (mkdir-p tmp) + (with-directory-excursion tmp + (invoke (string-append #$binutils-final "/bin/ar") + "x" #$source)) + + ;; 2. Volcar contenido al output + ;; El data.tar.xz tiene rutas ./usr/bin/, ./usr/sbin/, + ;; ./usr/lib/, ./usr/share/ → strip 2 componentes (. y usr) + (mkdir-p out) + (invoke (string-append #$tar "/bin/tar") + "xf" (string-append tmp "/data.tar.xz") + "--use-compress-program" + (string-append #$xz "/bin/xz") + "-C" out + "--strip-components=2") + + ;; 3. Parchear intérprete ELF y rpath de los binarios principales + ;; Las libs del bundle están en lib/mullvad-vpn/ + (let ((interp (string-append #$glibc "/lib/ld-linux-x86-64.so.2")) + (rpath (string-append out "/lib/mullvad-vpn"))) + (for-each + (lambda (rel-path) + (let ((bin (string-append out "/" rel-path))) + (when (file-exists? bin) + (invoke (string-append #$patchelf "/bin/patchelf") + "--set-interpreter" interp + "--set-rpath" rpath + bin)))) + '("sbin/mullvad-daemon" + "bin/mullvad")))))) + + (home-page "https://mullvad.net") + (synopsis "Cliente VPN centrado en la privacidad") + (description + "Mullvad VPN es un servicio de red privada virtual que no requiere +cuenta de usuario: se accede con un número de cuenta anónimo. Incluye +el demonio mullvad-daemon y el cliente de línea de comandos mullvad.") + (license license:gpl3+))) blob - e69de29bb2d1d6434b8b29ae775ad8c2e48c5391 blob + c7224165f6b234dbaf042f71fcaae26038106747 --- richard/packages/zen-browser.scm +++ richard/packages/zen-browser.scm @@ -0,0 +1,140 @@ +;; richard/packages/zen-browser.scm +;; +;; Paquete Zen Browser para canal Guix personal. +;; Estrategia: binary wrap — descarga el tarball oficial, parchea +;; el intérprete ELF con patchelf y crea un wrapper shell. +;; +;; Para actualizar a una versión nueva: +;; 1. Cambia 'version' al nuevo tag (ej. "1.13.0b") +;; 2. Obtén el hash nuevo: +;; guix download https://github.com/zen-browser/desktop/releases/download/VERSION/zen.linux-x86_64.tar.xz +;; 3. Reemplaza el (base32 "...") con el hash que devuelve ese comando + +(define-module (richard packages zen-browser) + #:use-module (guix packages) + #:use-module (guix download) + #:use-module (guix build-system trivial) + #:use-module (guix gexp) + #:use-module ((guix licenses) #:prefix license:) + #:use-module (gnu packages base) ; glibc, tar + #:use-module (gnu packages compression) ; xz + #:use-module (gnu packages elf) ; patchelf + #:export (zen-browser)) + +(define-public zen-browser + (package + (name "zen-browser") + (version "1.12.9b") + + ;; ── Fuente: tarball oficial de GitHub releases ────────────────── + (source + (origin + (method url-fetch) + (uri (string-append + "https://github.com/zen-browser/desktop/releases/download/" + version "/zen.linux-x86_64.tar.xz")) + (sha256 + ;; Hash obtenido con: guix download + ;; Si hay discrepancia, re-corre ese comando y actualiza aquí + (base32 + "0zjck0yqly6lbyj4njdjcj0p0fwv9k69lx4rwks53f72caqs95hs")))) + + (build-system trivial-build-system) + + ;; ── Dependencias en tiempo de compilación ────────────────────── + ;; (solo se usan para construir/instalar, no en runtime) + (native-inputs + (list tar xz patchelf)) + + ;; ── Dependencias en runtime ──────────────────────────────────── + ;; glibc: proporciona el intérprete ELF ld-linux-x86-64.so.2 + (inputs + (list glibc)) + + ;; ── Build ────────────────────────────────────────────────────── + (arguments + (list + #:modules '((guix build utils)) + #:builder + #~(begin + (use-modules (guix build utils)) + + ;; Rutas de salida e inputs + (define out #$output) + (define lib-dir (string-append out "/lib/zen-browser")) + (define bin-dir (string-append out "/bin")) + (define apps-dir (string-append out "/share/applications")) + (define icons-dir + (string-append out "/share/icons/hicolor/128x128/apps")) + + ;; 1. Extraer el tarball en lib/zen-browser/ + (mkdir-p lib-dir) + (invoke (string-append #$tar "/bin/tar") + "xf" #$source + "--use-compress-program" + (string-append #$xz "/bin/xz") + "-C" lib-dir + "--strip-components=1") + + ;; 2. Parchear intérprete ELF del ejecutable principal + ;; Sin esto, el binario no encuentra el loader de Guix + (invoke (string-append #$patchelf "/bin/patchelf") + "--set-interpreter" + (string-append #$glibc "/lib/ld-linux-x86-64.so.2") + (string-append lib-dir "/zen")) + + ;; 3. Crear wrapper en bin/ que: + ;; - Pone las libs del bundle en LD_LIBRARY_PATH + ;; - Habilita Wayland + ;; - Pasa todos los argumentos al binario real + (mkdir-p bin-dir) + (let ((wrapper (string-append bin-dir "/zen-browser"))) + (call-with-output-file wrapper + (lambda (port) + (format port + "#!/bin/sh +# Wrapper generado por Guix — no edites manualmente +export LD_LIBRARY_PATH=\"~a:$LD_LIBRARY_PATH\" +export MOZ_ENABLE_WAYLAND=1 +export MOZ_USE_XINPUT2=1 +exec \"~a/zen\" \"$@\" +" + lib-dir lib-dir))) + (chmod wrapper #o755)) + + ;; 4. Entrada .desktop para el lanzador de KDE + (mkdir-p apps-dir) + (call-with-output-file + (string-append apps-dir "/zen-browser.desktop") + (lambda (port) + (format port + "[Desktop Entry] +Name=Zen Browser +GenericName=Navegador Web +Comment=Un navegador tranquilo basado en Firefox +Exec=zen-browser %u +Icon=zen-browser +Terminal=false +Type=Application +Categories=Network;WebBrowser; +MimeType=text/html;text/xml;application/xhtml+xml;x-scheme-handler/http;x-scheme-handler/https; +StartupWMClass=zen +"))) + + ;; 5. Ícono: copiar del bundle si existe + (mkdir-p icons-dir) + (let ((icon + (string-append lib-dir + "/browser/chrome/icons/default/default128.png"))) + (when (file-exists? icon) + (copy-file icon + (string-append icons-dir "/zen-browser.png"))))))) + + (home-page "https://zen-browser.app") + (synopsis "Navegador web basado en Firefox, enfocado en privacidad") + (description + "Zen Browser es un fork de Firefox que prioriza la privacidad y +una experiencia de navegación más tranquila. Incluye una barra lateral +personalizable, gestión de espacios de trabajo y bloqueo de rastreadores.") + ;; Zen Browser hereda la licencia de Firefox + (license license:mpl2.0))) blob - /dev/null blob + b1d5bd35a83a5aa3d9c5c8fdcb1ffb6a3f783f04 (mode 644) --- /dev/null +++ richard/services/mullvad.scm @@ -0,0 +1,66 @@ +;; richard/services/mullvad.scm +;; +;; Servicio Shepherd para mullvad-daemon. +;; Gestiona el túnel WireGuard y el killswitch de Mullvad VPN. +;; +;; Uso en config.scm: +;; (use-modules ... (richard services mullvad)) +;; ;; En la lista de servicios: +;; (mullvad-service) + +(define-module (richard services mullvad) + #:use-module (guix gexp) + #:use-module (gnu services) + #:use-module (gnu services shepherd) + #:use-module (gnu services configuration) ; activation-service-type + #:use-module (richard packages mullvad) + #:export (mullvad-service-type + mullvad-service)) + +;; ── Activación: directorios que necesita el daemon ────────────────── +(define %mullvad-activation + #~(begin + (use-modules (guix build utils)) + ;; Configuración y estado persistente del daemon + (mkdir-p "/var/cache/mullvad-vpn") + ;; Directorio de logs + (mkdir-p "/var/log/mullvad-vpn"))) + +;; ── Servicio Shepherd ──────────────────────────────────────────────── +(define %mullvad-shepherd-service + (shepherd-service + (documentation "Mullvad VPN daemon — gestiona WireGuard y killswitch") + (provision '(mullvad)) + ;; networking asegura que la pila de red esté lista antes de arrancar + (requirement '(networking)) + (start + #~(make-forkexec-constructor + (list #$(file-append mullvad-vpn "/sbin/mullvad-daemon") + "--disable-stdout-timestamps") + #:log-file "/var/log/mullvad-vpn/daemon.log")) + (stop #~(make-kill-destructor)) + ;; Reiniciar automáticamente si el daemon cae inesperadamente + (respawn? #t))) + +;; ── Tipo de servicio ───────────────────────────────────────────────── +(define mullvad-service-type + (service-type + (name 'mullvad) + (extensions + (list + ;; Registra el servicio con Shepherd + (service-extension shepherd-root-service-type + (const (list %mullvad-shepherd-service))) + ;; Instala mullvad-vpn en el perfil del sistema + (service-extension profile-service-type + (const (list mullvad-vpn))) + ;; Crea /var/cache/mullvad-vpn y /var/log/mullvad-vpn al boot + (service-extension activation-service-type + (const %mullvad-activation)))) + (default-value #f) + (description + "Ejecuta mullvad-daemon, el proceso que gestiona la conexión VPN, +el túnel WireGuard y el killswitch de red de Mullvad VPN."))) + +(define (mullvad-service) + (service mullvad-service-type))