commit 9e74f4c6b993fae893b2a32e1f21efa363e99828 from: Alejandro Bernal Estrada date: Thu May 21 20:14:07 2026 UTC fix: corregir paths de extracción del .deb y módulo activation-service-type commit - 7e9ac3af680cbbe3fe144d28ecfaf25a53c4e0ac commit + 9e74f4c6b993fae893b2a32e1f21efa363e99828 blob - 0504e3209093219c69b471406d3edc4a508ee657 blob + 66d62ee2b269048753d06a067f6f21688d4fbb04 --- richard/packages/mullvad.scm +++ richard/packages/mullvad.scm @@ -8,11 +8,7 @@ ;; 1. Cambia 'version' al nuevo tag (ej. "2026.2") ;; 2. Descarga el .deb y obtén el hash: ;; wget https://github.com/mullvad/mullvadvpn-app/releases/download/VERSION/MullvadVPN-VERSION_amd64.deb -;; sha256sum MullvadVPN-VERSION_amd64.deb | python3 -c " -;; import sys; h=input().split()[0] -;; NIX='0123456789abcdfghijklmnpqrsvwxyz' -;; d=bytes.fromhex(h); n=(len(d)*8+4)//5 -;; print(''.join(NIX[(int.from_bytes(d[b//8:b//8+2],'big')>>(11-b%8))&31] for b in [i*5 for i in range(n-1,-1,-1)]))" +;; sha256sum MullvadVPN-VERSION_amd64.deb | python3 ~/nix32.py $(cut -d' ' -f1) ;; 3. Reemplaza el (base32 "...") con el resultado (define-module (richard packages mullvad) @@ -58,45 +54,75 @@ #~(begin (use-modules (guix build utils)) - (define out #$output) - (define tmp "/tmp/mullvad-work") + (define out #$output) + (define tmp "/tmp/mullvad-work") + (define lib-dir (string-append out "/lib/mullvad-vpn")) + (define bin-dir (string-append out "/bin")) - ;; 1. Extraer data.tar.xz del .deb (formato ar) + ;; ── 1. Extraer data.tar.xz del .deb ───────────────────── + ;; Un .deb es un archivo ar que contiene: + ;; control.tar.xz — metadatos del paquete + ;; data.tar.xz — los archivos reales (mkdir-p tmp) (with-directory-excursion tmp (invoke (string-append #$binutils-final "/bin/ar") - "x" #$source)) + "x" #$source) + ;; Extraer sin --strip-components: Mullvad instala en + ;; ./opt/Mullvad VPN/ (con espacio), no en /usr/ + (invoke (string-append #$tar "/bin/tar") + "xf" "data.tar.xz" + "--use-compress-program" + (string-append #$xz "/bin/xz"))) - ;; 2. Volcar contenido al output - ;; El data.tar.xz tiene rutas ./usr/bin/, ./usr/sbin/, - ;; ./usr/lib/, ./usr/share/ → strip 2 componentes (. y usr) - (mkdir-p out) - (invoke (string-append #$tar "/bin/tar") - "xf" (string-append tmp "/data.tar.xz") - "--use-compress-program" - (string-append #$xz "/bin/xz") - "-C" out - "--strip-components=2") + ;; ── 2. Copiar el bundle al store ────────────────────────── + ;; Usamos copy-recursively para manejar el espacio en el path + ;; "Mullvad VPN" sin problemas de shell + (define app-src (string-append tmp "/opt/Mullvad VPN")) + (mkdir-p lib-dir) + (copy-recursively app-src lib-dir) - ;; 3. Parchear intérprete ELF y rpath de los binarios principales - ;; Las libs del bundle están en lib/mullvad-vpn/ - (let ((interp (string-append #$glibc "/lib/ld-linux-x86-64.so.2")) - (rpath (string-append out "/lib/mullvad-vpn"))) + ;; ── 3. Parchear intérprete ELF + rpath ─────────────────── + ;; El intérprete apunta al loader de glibc en el store de Guix + ;; El rpath permite encontrar las libs del bundle en lib-dir + (let ((interp + (string-append #$glibc "/lib/ld-linux-x86-64.so.2"))) (for-each - (lambda (rel-path) - (let ((bin (string-append out "/" rel-path))) + (lambda (bin-name) + (let ((bin (string-append lib-dir "/" bin-name))) (when (file-exists? bin) (invoke (string-append #$patchelf "/bin/patchelf") "--set-interpreter" interp - "--set-rpath" rpath + "--set-rpath" lib-dir bin)))) - '("sbin/mullvad-daemon" - "bin/mullvad")))))) + ;; Binarios principales del bundle de Mullvad + '("mullvad-daemon" + "mullvad"))) + ;; ── 4. Wrappers en bin/ ─────────────────────────────────── + ;; Scripts delgados que invocan los binarios en lib-dir + (mkdir-p bin-dir) + (for-each + (lambda (bin-name) + (let ((wrapper (string-append bin-dir "/" bin-name))) + (call-with-output-file wrapper + (lambda (port) + (format port + "#!/bin/sh\nexec \"~a/~a\" \"$@\"\n" + lib-dir bin-name))) + (chmod wrapper #o755))) + '("mullvad-daemon" "mullvad")) + + ;; ── 5. Compartir .desktop e íconos del bundle ───────────── + (let ((share-src (string-append tmp "/usr/share"))) + (when (file-exists? share-src) + (copy-recursively share-src + (string-append out "/share"))))))) + (home-page "https://mullvad.net") (synopsis "Cliente VPN centrado en la privacidad") (description "Mullvad VPN es un servicio de red privada virtual que no requiere -cuenta de usuario: se accede con un número de cuenta anónimo. Incluye -el demonio mullvad-daemon y el cliente de línea de comandos mullvad.") +cuenta de usuario: se accede con un número de cuenta anónimo. Este +paquete instala el demonio @command{mullvad-daemon} y el cliente de +línea de comandos @command{mullvad}.") (license license:gpl3+))) blob - b1d5bd35a83a5aa3d9c5c8fdcb1ffb6a3f783f04 blob + d21451be09d990eafa9e0f5cbd67fce7b6e65282 --- richard/services/mullvad.scm +++ richard/services/mullvad.scm @@ -3,27 +3,25 @@ ;; Servicio Shepherd para mullvad-daemon. ;; Gestiona el túnel WireGuard y el killswitch de Mullvad VPN. ;; -;; Uso en config.scm: -;; (use-modules ... (richard services mullvad)) -;; ;; En la lista de servicios: +;; Uso en /etc/config.scm: +;; (use-modules (richard services mullvad)) +;; +;; ;; En el bloque (services ...): ;; (mullvad-service) (define-module (richard services mullvad) #:use-module (guix gexp) - #:use-module (gnu services) - #:use-module (gnu services shepherd) - #:use-module (gnu services configuration) ; activation-service-type + #:use-module (gnu services) ; activation-service-type, profile-service-type + #:use-module (gnu services shepherd) ; shepherd-service, shepherd-root-service-type #:use-module (richard packages mullvad) #:export (mullvad-service-type mullvad-service)) -;; ── Activación: directorios que necesita el daemon ────────────────── +;; ── Activación: crea directorios necesarios al arranque ───────────── (define %mullvad-activation #~(begin (use-modules (guix build utils)) - ;; Configuración y estado persistente del daemon (mkdir-p "/var/cache/mullvad-vpn") - ;; Directorio de logs (mkdir-p "/var/log/mullvad-vpn"))) ;; ── Servicio Shepherd ──────────────────────────────────────────────── @@ -31,15 +29,16 @@ (shepherd-service (documentation "Mullvad VPN daemon — gestiona WireGuard y killswitch") (provision '(mullvad)) - ;; networking asegura que la pila de red esté lista antes de arrancar + ;; networking: espera a que la pila de red esté lista (requirement '(networking)) (start #~(make-forkexec-constructor - (list #$(file-append mullvad-vpn "/sbin/mullvad-daemon") + ;; El daemon está en lib/mullvad-vpn/ dentro del store + (list #$(file-append mullvad-vpn "/lib/mullvad-vpn/mullvad-daemon") "--disable-stdout-timestamps") #:log-file "/var/log/mullvad-vpn/daemon.log")) (stop #~(make-kill-destructor)) - ;; Reiniciar automáticamente si el daemon cae inesperadamente + ;; Reiniciar automáticamente si el daemon cae (respawn? #t))) ;; ── Tipo de servicio ───────────────────────────────────────────────── @@ -51,7 +50,7 @@ ;; Registra el servicio con Shepherd (service-extension shepherd-root-service-type (const (list %mullvad-shepherd-service))) - ;; Instala mullvad-vpn en el perfil del sistema + ;; Instala mullvad-vpn (CLI + daemon) en el perfil del sistema (service-extension profile-service-type (const (list mullvad-vpn))) ;; Crea /var/cache/mullvad-vpn y /var/log/mullvad-vpn al boot @@ -59,8 +58,9 @@ (const %mullvad-activation)))) (default-value #f) (description - "Ejecuta mullvad-daemon, el proceso que gestiona la conexión VPN, -el túnel WireGuard y el killswitch de red de Mullvad VPN."))) + "Ejecuta @command{mullvad-daemon}, el proceso que gestiona la +conexión VPN, el túnel WireGuard y el killswitch de Mullvad VPN."))) +;; Función de conveniencia para usar en config.scm (define (mullvad-service) (service mullvad-service-type))