aboutsummaryrefslogtreecommitdiff
path: root/assets/outbox/2026-06-24-lint-followups-resolved.org
diff options
context:
space:
mode:
authorCraig Jennings <c@cjennings.net>2026-09-13 07:02:39 -0500
committerCraig Jennings <c@cjennings.net>2026-09-13 07:02:39 -0500
commit20196051d9cd25d775373a48fcf05dc258497301 (patch)
treee97e1707f14584b025b206503d7475b4f5da84ef /assets/outbox/2026-06-24-lint-followups-resolved.org
parent1d0ede0727f53c9e65faf09b3fddf6c1962da88f (diff)
downloadarchsetup-20196051d9cd25d775373a48fcf05dc258497301.tar.gz
archsetup-20196051d9cd25d775373a48fcf05dc258497301.zip
feat(install): default DNS over TLS off on the Proton tunnel links
The resolved drop-in pins DNSOverTLS=yes for every link. Proton VPN (proton0) and the static Proton WireGuard profiles (wgpvpn) push an in-tunnel resolver (10.2.0.1) that answers plain port 53 and never completes TLS on 853, so every lookup through the tunnel hung. The Proton client recreates its NetworkManager profile on each connect, so a per-profile setting can't stick. NM pushes a [connection-tunnel-dot] default matched on those two interface names to resolved on every activation. Wifi and everything else keep the strict setting. Ratio and velox already carry the drop-in by hand. This makes a rebuild carry it too.
Diffstat (limited to 'assets/outbox/2026-06-24-lint-followups-resolved.org')
0 files changed, 0 insertions, 0 deletions