Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

⚠️ IMPORTANT: THIS PROJECT IS ENTIRELY AI-DEVELOPED

Caution

GPC Connect — including its C source code, privileged helper, PolicyKit policy, installation scripts, packaging, documentation, and architecture — has been developed entirely with artificial intelligence.

The project is published openly so that its implementation can be inspected, tested, audited, improved, and corrected by the community. AI-generated code can contain mistakes and must not be treated as automatically safe or production-ready. This application manages a VPN and installs a narrowly scoped privileged helper. Review the source and scripts before using them, especially on corporate, university, or security-sensitive systems.

The software is provided without warranty. Use it at your own risk.

GPC Connect

GPC Connect is a free and open-source GTK4 client written in C for managing Palo Alto GlobalProtect VPN connections through the open-source gpauth and gpclient command-line tools.

It provides multiple saved profiles, browser-based SSO, live logs, a native StatusNotifierItem tray icon, and a constrained PolicyKit helper that avoids requiring administrator credentials for every connection.

Licensed under GPL-3.0-or-later. GPC Connect is not affiliated with or endorsed by Palo Alto Networks.

Features

  • Multiple VPN profiles stored in the user's configuration directory
  • Browser SSO through the default browser, Firefox, Chrome, or Chromium
  • Live connection logs with normal, debug, and trace levels
  • Native KDE Plasma/Wayland tray integration using StatusNotifierItem
  • Reopen, disconnect, and fully quit from the tray menu
  • Credentials and authentication cookies are never written to disk
  • Restricted root-owned helper with a dedicated PolicyKit action
  • Single-command installer and uninstaller
  • Completely free and open source

Quick installation

Warning

wget | sh executes code downloaded from the internet. The shortest command is provided for convenience, but the safer method is to download and inspect install.sh before running it.

One command

wget -qO- https://github.com/marcolvr/gpc-connect/raw/refs/heads/main/install.sh | sh

Using curl instead:

curl -fsSL https://github.com/marcolvr/gpc-connect/raw/refs/heads/main/install.sh | sh

Recommended: inspect before running

wget -O install.sh https://github.com/marcolvr/gpc-connect/raw/refs/heads/main/install.sh
less install.sh
sh install.sh

The installer will:

  1. Detect the Linux distribution and CPU architecture.
  2. Run preflight checks for administrative access, disk space, TUN support, networking tools, and a graphical session.
  3. Install GTK4 development files, a C toolchain, PolicyKit, and other required packages through the native package manager.
  4. Install the latest compatible GlobalProtect-openconnect release when gpclient and gpauth are missing.
  5. Resolve and download the latest GPC Connect GitHub release. Before the first release exists, it falls back to the current main branch snapshot.
  6. Extract the source into a temporary directory, build it, and install it into /usr.
  7. Refresh the desktop application and icon caches when the relevant tools are available.
  8. Remove its temporary files and exit.

The installer is idempotent: running it again updates the application while preserving saved profiles.

Supported distributions

Family Distributions Dependency source
Debian/Ubuntu Debian 13+, Ubuntu, Linux Mint, Pop!_OS, Zorin OS, elementary OS APT + latest upstream .deb
Fedora Fedora Workstation and Fedora spins DNF + upstream COPR, with RPM fallback
RHEL family RHEL, Rocky Linux, AlmaLinux, CentOS Stream DNF + latest upstream .rpm
Arch family Arch Linux, EndeavourOS, Manjaro, Garuda Linux Pacman repository, with package fallback
openSUSE Tumbleweed and Leap 15.6+ Zypper + latest upstream .rpm
Alpine Current Alpine Linux APK + latest upstream .apk
Gentoo Gentoo with the Guru repository Portage/Guru
Void Void Linux XBPS + upstream generic binary bundle

Only x86_64 and aarch64 are currently supported by the universal installer. NixOS is intentionally not handled because installing mutable files under /usr conflicts with the NixOS model; a native derivation is required.

Very old distributions may be unable to run the latest GlobalProtect-openconnect binaries because of system library requirements.

Launching the application

After installation, launch GPC Connect from the desktop application menu or run:

gpc-connect

Create a profile, enter the GlobalProtect portal hostname, choose a browser, save, and press Connect. Closing the main window keeps the application in the system tray. Use Exit completely from the tray menu to disconnect the VPN and terminate the background process.

GNOME does not display StatusNotifierItem icons by default. Install and enable an AppIndicator/StatusNotifier extension if the tray icon is not visible.

Uninstallation

Remove GPC Connect while keeping saved VPN profiles:

wget -qO- https://github.com/marcolvr/gpc-connect/raw/refs/heads/main/uninstall.sh | sh

Remove the application and the current user's saved profiles:

wget -qO- https://github.com/marcolvr/gpc-connect/raw/refs/heads/main/uninstall.sh | sh -s -- --purge

The uninstaller disconnects an active tunnel when possible, stops the current user's GPC Connect process, and removes the installed binary, helper, PolicyKit policy, desktop entry, metadata, and icon.

It deliberately does not remove GlobalProtect-openconnect, GTK4, PolicyKit, or build tools because they may be used by other software.

Manual build and installation

Requirements

  • A C17 compiler such as GCC or Clang
  • GNU Make
  • pkg-config
  • GTK4 and GIO development files
  • PolicyKit and pkexec
  • gpclient and gpauth from GlobalProtect-openconnect

Example for Fedora:

sudo dnf install gcc make pkgconf-pkg-config gtk4-devel polkit
sudo dnf copr enable yuezk/globalprotect-openconnect
sudo dnf install globalprotect-openconnect

Build and run without installing:

git clone https://github.com/marcolvr/gpc-connect.git
cd gpc-connect
make
./gpc-connect

Without system installation, the restricted PolicyKit helper is unavailable and pkexec may request administrator authentication. Install the complete application with:

sudo make install

To create the source tarball or an RPM:

make dist
rpmbuild -ta gpc-connect-0.3.0.tar.gz

How it works

  1. Profiles are stored without credentials in ~/.config/gpc-connect/profiles.ini.
  2. gpauth runs as the desktop user and opens the selected browser for SSO.
  3. The returned authentication cookie remains only in memory.
  4. The cookie is passed through standard input to /usr/libexec/gpc-connect-helper via pkexec.
  5. The root-owned helper validates a fixed operation and a small set of options, clears its environment, and executes /usr/bin/gpclient without invoking a shell.
  6. The tunnel process stays attached to GPC Connect so logs and lifecycle are visible and controllable.
  7. The tray icon is exported over the session D-Bus using the StatusNotifierItem and DBusMenu protocols.

The supplied PolicyKit rule uses yes for active local sessions. Administrator credentials are not required for normal VPN connections after installation.

Security notes

  • Read install.sh, uninstall.sh, src/helper.c, and the PolicyKit policy before deployment in a managed environment.
  • Do not enable Ignore TLS errors unless you understand and accept the risk.
  • The one-line installer trusts HTTPS, GitHub, this repository, the detected distribution repositories, and the upstream GlobalProtect-openconnect release artifacts.
  • An administrator is still required once to install packages and protected system files.
  • Report security issues privately to the maintainer before publishing details.

Project status and contributions

This is an early-stage community project. Testing, code review, packaging, translations, accessibility work, and support for additional distributions are welcome. AI-assisted and human-written contributions should be clearly reviewed and tested before merging.

License

Copyright © 2026 Marco Lavarini.

GPC Connect is free software distributed under the GNU General Public License, version 3 or any later version. See LICENSE.

About

Manage VPN GlobalProtect Connection through gpclient with a simple and minimal GUI

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages