Files
box/bin/netvm-proton.sh
T

37 lines
1.9 KiB
Bash
Raw Normal View History

#!/usr/bin/env bash
# netvm-proton.sh <profile> -- <proton-cli args...>
# Run proton-cli as the profile's Proton identity, inside the profile's netns
# (Warp egress) and inside a bwrap filesystem jail.
# 1:1:1: profile = node = warp identity = proton-cli profile.
# Human creates the session once: proton-cli -p <profile> account login.
# (Credential setup itself belongs to pix; see proton-ingest design D6.)
set -euo pipefail
NETVM_BIN="$(cd "$(dirname "$0")" && pwd)"
NODE="${1:?usage: netvm-proton.sh <profile> -- <proton-cli args...>}"; shift
[ "${1:-}" = "--" ] && shift
[ $# -gt 0 ] || { echo "usage: netvm-proton.sh <profile> -- <proton-cli args...>"; exit 1; }
[ -f "/etc/netvm/${NODE}.conf" ] || { echo "no warp identity for '$NODE' (human: netvm-new-identity.sh $NODE)"; exit 1; }
command -v bwrap >/dev/null 2>&1 || { echo "bwrap not found" >&2; exit 1; }
command -v proton-cli >/dev/null 2>&1 || { echo "proton-cli not found" >&2; exit 1; }
PCLI_HOME="$HOME/.config/proton-cli"
[ -d "$PCLI_HOME" ] || { echo "no proton-cli config dir (human: proton-cli account login)"; exit 1; }
PCLI_BIN="$(readlink -f "$(command -v proton-cli)")"
[ -x "$PCLI_BIN" ] || { echo "proton-cli binary not executable: $PCLI_BIN"; exit 1; }
# Jail: whole home is tmpfs except the proton-cli config (rw: sessions refresh,
# logs), the resolved static binary (ro), and a scratch tmp. proton-cli needs
# nothing else on disk.
BWRAP=(bwrap --unshare-uts --unshare-ipc --die-with-parent
--ro-bind / / --dev /dev --proc /proc --tmpfs /tmp --tmpfs /dev/shm
--tmpfs "$HOME" --dir "$HOME/.config"
--bind "$PCLI_HOME" "$HOME/.config/proton-cli"
--ro-bind "$PCLI_BIN" /tmp/proton-cli
--setenv HOME "$HOME" --setenv PATH /usr/bin:/bin
--setenv PROTON_PROFILE "$NODE"
--setenv PROTON_NO_INPUT 1
--unsetenv DISPLAY --unsetenv WAYLAND_DISPLAY --unsetenv XDG_RUNTIME_DIR)
exec sudo -n "$NETVM_BIN/netvm-enter.sh" "$NODE" "$(id -u)" "$(id -g)" "$HOME" \
-- "${BWRAP[@]}" -- /tmp/proton-cli "$@"