#!/bin/sh
# Installed root-owned. Invoked explicitly through administrator authentication.
set -eu
if [ "$(/usr/bin/id -u)" -ne 0 ]; then
    echo 'Administrator authentication required.' >&2
    exit 1
fi
# Stop this service before removing its firewall, so it cannot re-arm it.
/usr/bin/systemctl stop publicvpnlist.service
/usr/lib/publicvpnlist/pvld recover-network
echo 'VPN protection disabled; ordinary network access restored.'
# Restart only the idle helper. This does not initiate a VPN connection.
/usr/bin/systemctl start publicvpnlist.service
