e321300f67
Groundwork for VPN mode; nothing calls it yet, so the module is dead code until the namespace bootstrap lands. vpn::config parses the ProtonVPN-style WireGuard INI into typed sections. `InterfaceSection` gets a hand-written Debug that redacts the private key — the derived one would print it verbatim, and this struct is about to start flowing through error contexts during interface setup. vpn::namespace::preflight checks user.max_user_namespaces and fails with the sysctl name and its remediation when unprivileged user namespaces are disabled. The decision logic is split into `evaluate` so the tests exercise the real code path rather than a copy of it — the /proc file itself cannot be mocked. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>