diff --git a/rootfs/etc/fstab b/rootfs/etc/fstab new file mode 100644 index 0000000..4461dcd --- /dev/null +++ b/rootfs/etc/fstab @@ -0,0 +1,17 @@ +# /dev/nvme0n1p2 +UUID=fd788a35-b3ee-48a4-9d7c-4f9bcdc46614 / btrfs rw,relatime,ssd,discard=async,space_cache=v2,subvolid=256,subvol=/@ 0 0 + +# /dev/nvme0n1p2 +UUID=fd788a35-b3ee-48a4-9d7c-4f9bcdc46614 /home btrfs rw,relatime,ssd,discard=async,space_cache=v2,subvolid=257,subvol=/@home 0 0 + +# /dev/nvme0n1p2 +UUID=fd788a35-b3ee-48a4-9d7c-4f9bcdc46614 /var/log btrfs rw,relatime,ssd,discard=async,space_cache=v2,subvolid=258,subvol=/@log 0 0 + +# /dev/nvme0n1p2 +UUID=fd788a35-b3ee-48a4-9d7c-4f9bcdc46614 /var/cache/pacman/pkg btrfs rw,relatime,ssd,discard=async,space_cache=v2,subvolid=259,subvol=/@pkg 0 0 + +# /dev/nvme0n1p1 +UUID=74CA-B4A5 /boot vfat rw,relatime,fmask=0022,dmask=0022,codepage=437,iocharset=ascii,shortname=mixed,utf8,errors=remount-ro 0 2 + +# /dev/nvme0n1p2 +UUID=fd788a35-b3ee-48a4-9d7c-4f9bcdc46614 /.snapshots btrfs rw,relatime,ssd,discard=async,space_cache=v2,subvol=/@/.snapshots 0 0 diff --git a/rootfs/etc/makepkg.conf b/rootfs/etc/makepkg.conf new file mode 100644 index 0000000..29ced97 --- /dev/null +++ b/rootfs/etc/makepkg.conf @@ -0,0 +1,174 @@ +#!/hint/bash +# shellcheck disable=2034 + +# +# /etc/makepkg.conf +# + +######################################################################### +# SOURCE ACQUISITION +######################################################################### +# +#-- The download utilities that makepkg should use to acquire sources +# Format: 'protocol::agent' +# DLAGENTS=('file::/usr/bin/curl -qgC - -o %o %u' +# 'ftp::/usr/bin/curl -qgfC - --ftp-pasv --retry 3 --retry-delay 3 -o %o %u' +# 'http::/usr/bin/curl -qgb "" -fLC - --retry 3 --retry-delay 3 -o %o %u' +# 'https::/usr/bin/curl -qgb "" -fLC - --retry 3 --retry-delay 3 -o %o %u' +# 'rsync::/usr/bin/rsync --no-motd -z %u %o' +# 'scp::/usr/bin/scp -C %u %o') + +# Other common tools: +# /usr/bin/snarf +# /usr/bin/lftpget -c +# /usr/bin/wget +DLAGENTS=('file::/usr/bin/curl -qgC - -o %o %u' + 'ftp::/usr/bin/axel -n 4 -a -o %o %u' + 'http::/usr/bin/axel -n 4 -a -o %o %u' + 'https::/usr/bin/axel -n 4 -a -o %o %u' + 'rsync::/usr/bin/rsync --no-motd -z %u %o' + 'scp::/usr/bin/scp -C %u %o') + +#-- The package required by makepkg to download VCS sources +# Format: 'protocol::package' +VCSCLIENTS=('bzr::breezy' + 'fossil::fossil' + 'git::git' + 'hg::mercurial' + 'svn::subversion') + +######################################################################### +# ARCHITECTURE, COMPILE FLAGS +######################################################################### +# +CARCH="x86_64" +CHOST="x86_64-pc-linux-gnu" + +#NPROC=2 + +#-- Compiler and Linker Flags +#CPPFLAGS="" +CFLAGS="-march=native -mtune=generic -O2 -pipe -fno-plt -fexceptions \ + -Wp,-D_FORTIFY_SOURCE=3 -Wformat -Werror=format-security \ + -fstack-clash-protection -fcf-protection \ + -fno-omit-frame-pointer -mno-omit-leaf-frame-pointer" +CXXFLAGS="$CFLAGS -Wp,-D_GLIBCXX_ASSERTIONS" +LDFLAGS="-Wl,-O1 -Wl,--sort-common -Wl,--as-needed -Wl,-z,relro -Wl,-z,now \ + -Wl,-z,pack-relative-relocsi -fuse-ld=mold" +LTOFLAGS="-flto=auto" +#-- Make Flags: change this for DistCC/SMP systems +MAKEFLAGS="-j12" +#-- Debugging flags +DEBUG_CFLAGS="-g" +DEBUG_CXXFLAGS="$DEBUG_CFLAGS" + +######################################################################### +# BUILD ENVIRONMENT +######################################################################### +# +# Makepkg defaults: BUILDENV=(!distcc !color !ccache check !sign) +# A negated environment option will do the opposite of the comments below. +# +#-- distcc: Use the Distributed C/C++/ObjC compiler +#-- color: Colorize output messages +#-- ccache: Use ccache to cache compilation +#-- check: Run the check() function if present in the PKGBUILD +#-- sign: Generate PGP signature file +# +BUILDENV=(!distcc color ccache check !sign) +# +#-- If using DistCC, your MAKEFLAGS will also need modification. In addition, +#-- specify a space-delimited list of hosts running in the DistCC cluster. +#DISTCC_HOSTS="" +# +#-- Specify a directory for package building. +BUILDDIR=$HOME/.cache/makepkg + +######################################################################### +# GLOBAL PACKAGE OPTIONS +# These are default values for the options=() settings +######################################################################### +# +# Makepkg defaults: +# OPTIONS=(!strip docs libtool staticlibs emptydirs !zipman !purge !debug !lto !autodeps) +# A negated option will do the opposite of the comments below. +# +#-- strip: Strip symbols from binaries/libraries +#-- docs: Save doc directories specified by DOC_DIRS +#-- libtool: Leave libtool (.la) files in packages +#-- staticlibs: Leave static library (.a) files in packages +#-- emptydirs: Leave empty directories in packages +#-- zipman: Compress manual (man and info) pages in MAN_DIRS with gzip +#-- purge: Remove files specified by PURGE_TARGETS +#-- debug: Add debugging flags as specified in DEBUG_* variables +#-- lto: Add compile flags for building with link time optimization +#-- autodeps: Automatically add depends/provides +# +OPTIONS=(strip docs !libtool !staticlibs emptydirs zipman purge debug lto) + +#-- File integrity checks to use. Valid: md5, sha1, sha224, sha256, sha384, sha512, b2 +INTEGRITY_CHECK=(sha256) +#-- Options to be used when stripping binaries. See `man strip' for details. +STRIP_BINARIES="--strip-all" +#-- Options to be used when stripping shared libraries. See `man strip' for details. +STRIP_SHARED="--strip-unneeded" +#-- Options to be used when stripping static libraries. See `man strip' for details. +STRIP_STATIC="--strip-debug" +#-- Manual (man and info) directories to compress (if zipman is specified) +MAN_DIRS=(usr{,/local}{,/share}/{man,info}) +#-- Doc directories to remove (if !docs is specified) +DOC_DIRS=(usr/{,local/}{,share/}{doc,gtk-doc}) +#-- Files to be removed from all packages (if purge is specified) +PURGE_TARGETS=(usr/{,share}/info/dir .packlist *.pod) +#-- Directory to store source code in for debug packages +DBGSRCDIR="/usr/src/debug" +#-- Prefix and directories for library autodeps +LIB_DIRS=('lib:usr/lib' 'lib32:usr/lib32') + +######################################################################### +# PACKAGE OUTPUT +######################################################################### +# +# Default: put built package and cached source in build directory +# +#-- Destination: specify a fixed directory where all packages will be placed +#PKGDEST=/home/packages +#-- Source cache: specify a fixed directory where source files will be cached +#SRCDEST=/home/sources +#-- Source packages: specify a fixed directory where all src packages will be placed +#SRCPKGDEST=/home/srcpackages +#-- Log files: specify a fixed directory where all log files will be placed +#LOGDEST=/home/makepkglogs +#-- Packager: name/email of the person or organization building packages +#PACKAGER="John Doe " +#-- Specify a key to use for package signing +#GPGKEY="" + +######################################################################### +# COMPRESSION DEFAULTS +######################################################################### +# +COMPRESSGZ=(gzip -c -f -n) +COMPRESSBZ2=(bzip2 -c -f) +COMPRESSXZ=(xz -c -z -) +COMPRESSZST=(zstd -c -T0 -3 -) +COMPRESSLRZ=(lrzip -q) +COMPRESSLZO=(lzop -q) +COMPRESSZ=(compress -c -f) +COMPRESSLZ4=(lz4 -q) +COMPRESSLZ=(lzip -c -f) + +######################################################################### +# EXTENSION DEFAULTS +######################################################################### +# +PKGEXT='.pkg.tar' +SRCEXT='.src.tar.gz' + +######################################################################### +# OTHER +######################################################################### +# +#-- Command used to run pacman as root, instead of trying sudo and su +#PACMAN_AUTH=() +# vim: set ft=sh ts=2 sw=2 et: diff --git a/rootfs/etc/mkinitcpio.conf b/rootfs/etc/mkinitcpio.conf new file mode 100644 index 0000000..07fd52a --- /dev/null +++ b/rootfs/etc/mkinitcpio.conf @@ -0,0 +1,81 @@ +# vim:set ft=sh: +# MODULES +# The following modules are loaded before any boot hooks are +# run. Advanced users may wish to specify all system modules +# in this array. For instance: +# MODULES=(usbhid xhci_hcd) +MODULES=() + +# BINARIES +# This setting includes any additional binaries a given user may +# wish into the CPIO image. This is run last, so it may be used to +# override the actual binaries included by a given hook +# BINARIES are dependency parsed, so you may safely ignore libraries +BINARIES=() + +# FILES +# This setting is similar to BINARIES above, however, files are added +# as-is and are not parsed in any way. This is useful for config files. +FILES=() + +# HOOKS +# This is the most important setting in this file. The HOOKS control the +# modules and scripts added to the image, and what happens at boot time. +# Order is important, and it is recommended that you do not change the +# order in which HOOKS are added. Run 'mkinitcpio -H ' for +# help on a given hook. +# 'base' is _required_ unless you know precisely what you are doing. +# 'udev' is _required_ in order to automatically load modules +# 'filesystems' is _required_ unless you specify your fs modules in MODULES +# Examples: +## This setup specifies all modules in the MODULES setting above. +## No RAID, lvm2, or encrypted root is needed. +# HOOKS=(base) +# +## This setup will autodetect all modules for your system and should +## work as a sane default +# HOOKS=(base udev autodetect microcode modconf block filesystems fsck) +# +## This setup will generate a 'full' image which supports most systems. +## No autodetection is done. +# HOOKS=(base udev microcode modconf block filesystems fsck) +# +## This setup assembles a mdadm array with an encrypted root file system. +## Note: See 'mkinitcpio -H mdadm_udev' for more information on RAID devices. +# HOOKS=(base udev microcode modconf keyboard keymap consolefont block mdadm_udev encrypt filesystems fsck) +# +## This setup loads an lvm2 volume group. +# HOOKS=(base udev microcode modconf block lvm2 filesystems fsck) +# +## This will create a systemd based initramfs which loads an encrypted root filesystem. +# HOOKS=(base systemd autodetect microcode modconf kms keyboard sd-vconsole sd-encrypt block filesystems fsck) +# +## NOTE: If you have /usr on a separate partition, you MUST include the +# usr and fsck hooks. +HOOKS=(base udev autodetect microcode modconf kms keyboard keymap consolefont numlock block filesystems fsck) + +# COMPRESSION +# Use this to compress the initramfs image. By default, zstd compression +# is used for Linux ≥ 5.9 and gzip compression is used for Linux < 5.9. +# Use 'cat' to create an uncompressed image. +#COMPRESSION="zstd" +#COMPRESSION="gzip" +#COMPRESSION="bzip2" +#COMPRESSION="lzma" +#COMPRESSION="xz" +#COMPRESSION="lzop" +#COMPRESSION="lz4" + +# COMPRESSION_OPTIONS +# Additional options for the compressor +#COMPRESSION_OPTIONS=() + +# MODULES_DECOMPRESS +# Decompress loadable kernel modules and their firmware during initramfs +# creation. Switch (yes/no). +# Enable to allow further decreasing image size when using high compression +# (e.g. xz -9e or zstd --long --ultra -22) at the expense of increased RAM usage +# at early boot. +# Note that any compressed files will be placed in the uncompressed early CPIO +# to avoid double compression. +#MODULES_DECOMPRESS="no" diff --git a/rootfs/etc/nftables.conf b/rootfs/etc/nftables.conf new file mode 100644 index 0000000..80c0cd0 --- /dev/null +++ b/rootfs/etc/nftables.conf @@ -0,0 +1,111 @@ +#!/usr/sbin/nft -f + +flush ruleset + +table inet filter { + + chain input { + type filter hook input priority 0; + policy drop; + + meta nftrace set 1 + + ct state established,related accept + iif "lo" accept + + # Autoriser les réponses des serveurs WireGuard vers notre client + iifname "wlp1s0" udp sport 51820 accept + + # Handshakes WireGuard sur wlan0 + iifname "wlp1s0" udp dport 51820 accept + iifname "wlp1s0" udp dport 51821 accept + + # Proton + iifname "wg0" udp dport 53 accept + iifname "wg0" tcp dport 53 accept + iifname "wg0" tcp dport 80 accept + iifname "wg0" tcp dport 443 accept + + # LAN local + iifname "wlp1s0" ip saddr 192.168.1.0/24 accept + + # VMs -> dnsmasq + iifname "virbr0" udp dport { 53, 67, 68 } accept + iifname "virbr0" tcp dport 53 accept + + iifname "virbr0" ct state established,related accept + iifname "virbr0" ip daddr 192.168.122.1 accept + + meta nfproto ipv6 drop + } + + chain forward { + type filter hook forward priority 0; + policy drop; + + # VMs -> Proton + iifname "virbr0" oifname "wg0" accept + iifname "wg0" oifname "virbr0" ct state established,related accept + + # VMs -> LAN + iifname "virbr0" oifname "wlp1s0" accept + iifname "wlp1s0" oifname "virbr0" ct state established,related accept + + iifname "virbr0" oifname "virbr0" accept +} + + chain output { + type filter hook output priority 0; + policy drop; + + meta nftrace set 1 + + oif "lo" accept + + # Autoriser ping via Proton wg0 + oifname "wg0" ip protocol icmp accept + + # DNS via Proton wg0 + oifname "wg0" udp dport 53 accept + oifname "wg0" tcp dport 53 accept + + # HTTP / HTTPS via Proton wg0 (pacman, web, etc.) + oifname "wg0" tcp dport 80 accept + oifname "wg0" tcp dport 443 accept + oifname "wg0" tcp dport 2222 accept + oifname "wg0" tcp dport 2223 accept + oifname "wg0" tcp dport { 993, 587 } accept + + # Handshakes WG via wlan0 + oifname "wlp1s0" udp dport 51820 accept + oifname "wlp1s0" udp dport 51821 accept + + # sortie SSH 2222 vers le LAN + oifname "wlp1s0" ip daddr 192.168.1.0/24 tcp dport 2222 accept + oifname "wlp1s0" ip daddr 86.237.184.253 tcp dport 2222 accept + oifname "wlp1s0" ip daddr 192.168.1.0/24 tcp dport 2223 accept + oifname "wlp1s0" ip daddr 86.237.184.253 tcp dport 2223 accept + + # Accès à l'interface de la box (192.168.1.1) via le LAN + oifname "wlp1s0" ip daddr 192.168.1.1 tcp dport { 80, 443, 2222, 2223} accept + oifname "wlp1s0" ip daddr 192.168.1.1 icmp type echo-request accept + oifname "wlp1s0" ip daddr 192.168.1.0/24 accept + + # Handshakes WG qui passeraient DANS le tunnel Proton (si c'est voulu) + oifname "wg0" udp dport 51820 accept + oifname "wg0" udp dport 51821 accept + + oifname "virbr0" accept + + meta nfproto ipv6 drop + } +} + +table ip nat { + chain postrouting { + type nat hook postrouting priority srcnat; + policy accept; + + ip saddr 192.168.122.0/24 oifname "wg0" masquerade + } +} diff --git a/rootfs/etc/pacman.conf b/rootfs/etc/pacman.conf new file mode 100644 index 0000000..50ee2cf --- /dev/null +++ b/rootfs/etc/pacman.conf @@ -0,0 +1,101 @@ +# +# /etc/pacman.conf +# +# See the pacman.conf(5) manpage for option and repository directives + +# +# GENERAL OPTIONS +# +[options] +IgnorePkg = cliphist +# The following paths are commented out with their default values listed. +# If you wish to use different paths, uncomment and update the paths. +#RootDir = / +#DBPath = /var/lib/pacman/ +#CacheDir = /var/cache/pacman/pkg/ +#LogFile = /var/log/pacman.log +#GPGDir = /etc/pacman.d/gnupg/ +#HookDir = /etc/pacman.d/hooks/ +HoldPkg = pacman glibc +#XferCommand = /usr/bin/curl -L -C - -f -o %o %u +#XferCommand = /usr/bin/wget --passive-ftp -c -O %o %u +#CleanMethod = KeepInstalled +Architecture = auto + +#IgnorePkg = +#IgnorePkg = +#IgnoreGroup = + +#NoUpgrade = +#NoExtract = + +# Misc options +#UseSyslog +Color +#NoProgressBar +CheckSpace +VerbosePkgLists +ParallelDownloads = 5 +DownloadUser = alpm +#DisableSandbox +ILoveCandy + +# By default, pacman accepts packages signed by keys that its local keyring +# trusts (see pacman-key and its man page), as well as unsigned packages. +SigLevel = Required DatabaseOptional +LocalFileSigLevel = Optional +#RemoteFileSigLevel = Required + +# NOTE: You must run `pacman-key --init` before first using pacman; the local +# keyring can then be populated with the keys of all official Arch Linux +# packagers with `pacman-key --populate archlinux`. + +# +# REPOSITORIES +# - can be defined here or included from another file +# - pacman will search repositories in the order defined here +# - local/custom mirrors can be added here or in separate files +# - repositories listed first will take precedence when packages +# have identical names, regardless of version number +# - URLs will have $repo replaced by the name of the current repo +# - URLs will have $arch replaced by the name of the architecture +# +# Repository entries are of the format: +# [repo-name] +# Server = ServerName +# Include = IncludePath +# +# The header [repo-name] is crucial - it must be present and +# uncommented to enable the repo. +# + +# The testing repositories are disabled by default. To enable, uncomment the +# repo name header and Include lines. You can add preferred servers immediately +# after the header, and they will be used before the default mirrors. + +#[core-testing] +#Include = /etc/pacman.d/mirrorlist + +[core] +Include = /etc/pacman.d/mirrorlist + +#[extra-testing] +#Include = /etc/pacman.d/mirrorlist + +[extra] +Include = /etc/pacman.d/mirrorlist + +# If you want to run 32 bit applications on your x86_64 system, +# enable the multilib repositories as required here. + +#[multilib-testing] +#Include = /etc/pacman.d/mirrorlist + +[multilib] +Include = /etc/pacman.d/mirrorlist + +# An example of a custom package repository. See the pacman manpage for +# tips on creating your own repositories. +#[custom] +#SigLevel = Optional TrustAll +#Server = file:///home/custompkgs