Alexander e321300f67 feat(torad): add WireGuard config parser and user-namespace preflight
Groundwork for VPN mode; nothing calls it yet, so the module is dead code
until the namespace bootstrap lands.

vpn::config parses the ProtonVPN-style WireGuard INI into typed sections.
`InterfaceSection` gets a hand-written Debug that redacts the private
key — the derived one would print it verbatim, and this struct is about
to start flowing through error contexts during interface setup.

vpn::namespace::preflight checks user.max_user_namespaces and fails with
the sysctl name and its remediation when unprivileged user namespaces are
disabled. The decision logic is split into `evaluate` so the tests
exercise the real code path rather than a copy of it — the /proc file
itself cannot be mocked.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-15 00:17:33 +02:00
2026-07-03 19:10:26 +02:00
2026-07-03 19:10:26 +02:00
2026-07-03 19:10:26 +02:00
2026-07-02 17:02:49 +02:00
2026-07-03 22:21:18 +02:00
2026-07-25 12:44:20 +02:00
2026-07-03 22:21:18 +02:00
2026-07-03 19:10:26 +02:00
S
Description
No description provided
542 KiB
Languages
Rust 99.1%
Nix 0.9%