net-dns/dnscrypt-proxy: add 2.1.16

Signed-off-by: Sam James <sam@gentoo.org>
This commit is contained in:
Sam James
2026-06-22 09:19:36 +01:00
parent ab61897f9c
commit 4d79cc0ee1
4 changed files with 209 additions and 3 deletions

View File

@@ -1 +1,2 @@
DIST dnscrypt-proxy-2.1.15.tar.gz 4058547 BLAKE2B 26e97f051f0daf080292641ae8c3e4e89782db9fd0d61e24ae51e838379fda67769fcab61ee58adb01ab662b9a1c3dc47254e4146e4cff29d3d08963154a0988 SHA512 ab2f9194b7631430805d5556b6174a3b360cc1bc3302e070969f79c11850c4f87e7ba34a889ee466f3c857c3f576b458a5ce37bd75e675c44f16c95202957e4d
DIST dnscrypt-proxy-2.1.16.tar.gz 3595664 BLAKE2B 8a28995639b2fae1ecfe0eb3b88ce41973f5194f67aabf19b8dc28fbb7e2cf967c7208598f1f5effb22575bf3de96abefc1eb728f653f90ef4d3ea507ecd1a9d SHA512 cc43005cd88afd6d51da4aec994ef262eb944dbdf786cd113cc5f8e75ce4ba30bf4ed498f75d26b5dcc430f197439bdd6738e82ff2444e988f7b9ec367ed30b1

View File

@@ -0,0 +1,103 @@
# Copyright 1999-2026 Gentoo Authors
# Distributed under the terms of the GNU General Public License v2
EAPI=8
inherit fcaps go-module prefix systemd
DESCRIPTION="Flexible DNS proxy, with support for encrypted DNS protocols"
HOMEPAGE="https://github.com/DNSCrypt/dnscrypt-proxy"
if [[ ${PV} == 9999 ]]; then
EGIT_REPO_URI="https://github.com/DNSCrypt/dnscrypt-proxy.git"
inherit git-r3
else
SRC_URI="https://github.com/DNSCrypt/dnscrypt-proxy/archive/${PV}.tar.gz -> ${P}.tar.gz"
KEYWORDS="~amd64 ~arm ~arm64 ~ppc64 ~x86"
fi
LICENSE="Apache-2.0 BSD ISC MIT MPL-2.0"
SLOT="0"
RDEPEND="
acct-group/dnscrypt-proxy
acct-user/dnscrypt-proxy
"
DEPEND="${RDEPEND}"
BDEPEND=">=dev-lang/go-1.25"
FILECAPS=( cap_net_bind_service+ep usr/bin/dnscrypt-proxy )
PATCHES=(
"${FILESDIR}"/${PN}-2.1.16-config-full-paths.patch
)
src_compile() {
pushd "${PN}" >/dev/null || die
ego build -v -x -mod=readonly -mod=vendor
popd >/dev/null || die
}
src_test() {
cd "${PN}" || die
ego test -mod=vendor
}
src_install() {
pushd "${PN}" >/dev/null || die
dobin dnscrypt-proxy
eprefixify example-dnscrypt-proxy.toml
insinto /etc/dnscrypt-proxy
newins example-dnscrypt-proxy.toml dnscrypt-proxy.toml
doins example-{allowed,blocked}-{ips.txt,names.txt}
doins example-{cloaking-rules.txt,forwarding-rules.txt}
popd >/dev/null || die
insinto /usr/share/dnscrypt-proxy
doins -r "utils/generate-domains-blocklist/."
newinitd "${FILESDIR}"/dnscrypt-proxy.initd dnscrypt-proxy
newconfd "${FILESDIR}"/dnscrypt-proxy.confd dnscrypt-proxy
systemd_newunit "${FILESDIR}"/dnscrypt-proxy.service dnscrypt-proxy.service
systemd_newunit "${FILESDIR}"/dnscrypt-proxy.socket dnscrypt-proxy.socket
insinto /etc/logrotate.d
newins "${FILESDIR}"/dnscrypt-proxy.logrotate dnscrypt-proxy
einstalldocs
}
pkg_postinst() {
fcaps_pkg_postinst
if ! use filecaps; then
ewarn "'filecaps' USE flag is disabled"
ewarn "${PN} will fail to listen on port 53"
ewarn "please do one the following:"
ewarn "1) re-enable 'filecaps'"
ewarn "2) change port to > 1024"
ewarn "3) configure to run ${PN} as root (not recommended)"
ewarn
fi
if systemd_is_booted || has_version sys-apps/systemd; then
elog "Using systemd socket activation may cause issues with speed"
elog "latency and reliability of ${PN} and is discouraged by upstream"
elog "Existing installations advised to disable 'dnscrypt-proxy.socket'"
elog "It is disabled by default for new installations"
elog "check "$(systemd_get_systemunitdir)/${PN}.service" for details"
elog
fi
elog "After starting the service you will need to update your"
elog "${EROOT}/etc/resolv.conf and replace your current set of resolvers"
elog "with:"
elog
elog "nameserver 127.0.0.1"
elog
elog "Also see https://github.com/DNSCrypt/${PN}/wiki"
}

View File

@@ -1,4 +1,4 @@
# Copyright 1999-2025 Gentoo Authors
# Copyright 1999-2026 Gentoo Authors
# Distributed under the terms of the GNU General Public License v2
EAPI=8
@@ -23,11 +23,13 @@ RDEPEND="
acct-group/dnscrypt-proxy
acct-user/dnscrypt-proxy
"
DEPEND="${RDEPEND}"
BDEPEND=">=dev-lang/go-1.25"
FILECAPS=( cap_net_bind_service+ep usr/bin/dnscrypt-proxy )
PATCHES=(
"${FILESDIR}"/${PN}-2.1.11-config-full-paths.patch
"${FILESDIR}"/${PN}-2.1.16-config-full-paths.patch
)
src_compile() {
@@ -89,7 +91,6 @@ pkg_postinst() {
elog "It is disabled by default for new installations"
elog "check "$(systemd_get_systemunitdir)/${PN}.service" for details"
elog
fi
elog "After starting the service you will need to update your"

View File

@@ -0,0 +1,101 @@
--- a/dnscrypt-proxy/example-dnscrypt-proxy.toml
+++ b/dnscrypt-proxy/example-dnscrypt-proxy.toml
@@ -437,7 +437,7 @@ reject_ttl = 10
## See the `example-forwarding-rules.txt` file for an example
-# forwarding_rules = 'forwarding-rules.txt'
+# forwarding_rules = '@GENTOO_PORTAGE_EPREFIX@/etc/dnscrypt-proxy/forwarding-rules.txt'
###############################################################################
@@ -452,7 +452,7 @@ reject_ttl = 10
##
## See the `example-cloaking-rules.txt` file for an example
-# cloaking_rules = 'cloaking-rules.txt'
+# cloaking_rules = '@GENTOO_PORTAGE_EPREFIX@/etc/dnscrypt-proxy/cloaking-rules.txt'
## TTL used when serving entries in cloaking-rules.txt
@@ -504,7 +504,7 @@ cache_neg_max_ttl = 600
## check for connectivity and captive portals, along with hard-coded
## IP addresses to return.
-# map_file = 'example-captive-portals.txt'
+# map_file = '@GENTOO_PORTAGE_EPREFIX@/etc/dnscrypt-proxy/example-captive-portals.txt'
###############################################################################
@@ -535,8 +535,8 @@ cache_neg_max_ttl = 600
## openssl req -x509 -nodes -newkey rsa:2048 -days 5000 -sha256 -keyout localhost.pem -out localhost.pem
## See the documentation (wiki) for more information.
-# cert_file = 'localhost.pem'
-# cert_key_file = 'localhost.pem'
+# cert_file = '@GENTOO_PORTAGE_EPREFIX@/etc/dnscrypt-proxy/localhost.pem'
+# cert_key_file = '@GENTOO_PORTAGE_EPREFIX@/etc/dnscrypt-proxy/localhost.pem'
###############################################################################
@@ -771,7 +771,7 @@ urls = [
'https://download.dnscrypt.info/resolvers-list/v3/public-resolvers.md',
'https://cdn.jsdelivr.net/gh/DNSCrypt/dnscrypt-resolvers@master/v3/public-resolvers.md'
]
-cache_file = 'public-resolvers.md'
+cache_file = '@GENTOO_PORTAGE_EPREFIX@/var/cache/dnscrypt-proxy/public-resolvers.md'
minisign_key = 'RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3'
refresh_delay = 73
prefix = ''
@@ -784,7 +784,7 @@ urls = [
'https://download.dnscrypt.info/resolvers-list/v3/relays.md',
'https://cdn.jsdelivr.net/gh/DNSCrypt/dnscrypt-resolvers@master/v3/relays.md'
]
-cache_file = 'relays.md'
+cache_file = '@GENTOO_PORTAGE_EPREFIX@/var/cache/dnscrypt-proxy/relays.md'
minisign_key = 'RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3'
refresh_delay = 73
prefix = ''
@@ -793,13 +793,13 @@ prefix = ''
# [sources.odoh-servers]
# urls = ['https://raw.githubusercontent.com/DNSCrypt/dnscrypt-resolvers/master/v3/odoh-servers.md', 'https://download.dnscrypt.info/resolvers-list/v3/odoh-servers.md', 'https://cdn.jsdelivr.net/gh/DNSCrypt/dnscrypt-resolvers@master/v3/odoh-servers.md']
-# cache_file = 'odoh-servers.md'
+# cache_file = '@GENTOO_PORTAGE_EPREFIX@/var/cache/dnscrypt-proxy/odoh-servers.md'
# minisign_key = 'RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3'
# refresh_delay = 73
# prefix = ''
# [sources.odoh-relays]
# urls = ['https://raw.githubusercontent.com/DNSCrypt/dnscrypt-resolvers/master/v3/odoh-relays.md', 'https://download.dnscrypt.info/resolvers-list/v3/odoh-relays.md', 'https://cdn.jsdelivr.net/gh/DNSCrypt/dnscrypt-resolvers@master/v3/odoh-relays.md']
-# cache_file = 'odoh-relays.md'
+# cache_file = '@GENTOO_PORTAGE_EPREFIX@/var/cache/dnscrypt-proxy/odoh-relays.md'
# minisign_key = 'RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3'
# refresh_delay = 73
# prefix = ''
@@ -809,7 +809,7 @@ prefix = ''
# [sources.quad9-resolvers]
# urls = ['https://quad9.net/dnscrypt/quad9-resolvers.md']
# minisign_key = 'RWQBphd2+f6eiAqBsvDZEBXBGHQBJfeG6G+wJPPKxCZMoEQYpmoysKUN'
-# cache_file = 'quad9-resolvers.md'
+# cache_file = '@GENTOO_PORTAGE_EPREFIX@/var/cache/dnscrypt-proxy/quad9-resolvers.md'
# prefix = 'quad9-'
### Another example source, with resolvers censoring some websites not appropriate for children
@@ -817,7 +817,7 @@ prefix = ''
# [sources.parental-control]
# urls = ['https://raw.githubusercontent.com/DNSCrypt/dnscrypt-resolvers/master/v3/parental-control.md', 'https://download.dnscrypt.info/resolvers-list/v3/parental-control.md', 'https://cdn.jsdelivr.net/gh/DNSCrypt/dnscrypt-resolvers@master/v3/parental-control.md']
-# cache_file = 'parental-control.md'
+# cache_file = '@GENTOO_PORTAGE_EPREFIX@/var/cache/dnscrypt-proxy/parental-control.md'
# minisign_key = 'RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3'
### dnscry.pt servers - See https://www.dnscry.pt
@@ -825,7 +825,7 @@ prefix = ''
# [sources.dnscry-pt-resolvers]
# urls = ["https://www.dnscry.pt/resolvers.md"]
# minisign_key = "RWQM31Nwkqh01x88SvrBL8djp1NH56Rb4mKLHz16K7qsXgEomnDv6ziQ"
-# cache_file = "dnscry.pt-resolvers.md"
+# cache_file = "@GENTOO_PORTAGE_EPREFIX@/var/cache/dnscrypt-proxy/dnscry.pt-resolvers.md"
# refresh_delay = 73
# prefix = "dnscry.pt-"