37 lines
1.9 KiB
Bash
37 lines
1.9 KiB
Bash
|
|
#!/usr/bin/env bash
|
||
|
|
# netvm-proton.sh <profile> -- <proton-cli args...>
|
||
|
|
# Run proton-cli as the profile's Proton identity, inside the profile's netns
|
||
|
|
# (Warp egress) and inside a bwrap filesystem jail.
|
||
|
|
# 1:1:1: profile = node = warp identity = proton-cli profile.
|
||
|
|
# Human creates the session once: proton-cli -p <profile> account login.
|
||
|
|
# (Credential setup itself belongs to pix; see proton-ingest design D6.)
|
||
|
|
set -euo pipefail
|
||
|
|
NETVM_BIN="$(cd "$(dirname "$0")" && pwd)"
|
||
|
|
NODE="${1:?usage: netvm-proton.sh <profile> -- <proton-cli args...>}"; shift
|
||
|
|
[ "${1:-}" = "--" ] && shift
|
||
|
|
[ $# -gt 0 ] || { echo "usage: netvm-proton.sh <profile> -- <proton-cli args...>"; exit 1; }
|
||
|
|
[ -f "/etc/netvm/${NODE}.conf" ] || { echo "no warp identity for '$NODE' (human: netvm-new-identity.sh $NODE)"; exit 1; }
|
||
|
|
command -v bwrap >/dev/null 2>&1 || { echo "bwrap not found" >&2; exit 1; }
|
||
|
|
command -v proton-cli >/dev/null 2>&1 || { echo "proton-cli not found" >&2; exit 1; }
|
||
|
|
|
||
|
|
PCLI_HOME="$HOME/.config/proton-cli"
|
||
|
|
[ -d "$PCLI_HOME" ] || { echo "no proton-cli config dir (human: proton-cli account login)"; exit 1; }
|
||
|
|
PCLI_BIN="$(readlink -f "$(command -v proton-cli)")"
|
||
|
|
[ -x "$PCLI_BIN" ] || { echo "proton-cli binary not executable: $PCLI_BIN"; exit 1; }
|
||
|
|
|
||
|
|
# Jail: whole home is tmpfs except the proton-cli config (rw: sessions refresh,
|
||
|
|
# logs), the resolved static binary (ro), and a scratch tmp. proton-cli needs
|
||
|
|
# nothing else on disk.
|
||
|
|
BWRAP=(bwrap --unshare-uts --unshare-ipc --die-with-parent
|
||
|
|
--ro-bind / / --dev /dev --proc /proc --tmpfs /tmp --tmpfs /dev/shm
|
||
|
|
--tmpfs "$HOME" --dir "$HOME/.config"
|
||
|
|
--bind "$PCLI_HOME" "$HOME/.config/proton-cli"
|
||
|
|
--ro-bind "$PCLI_BIN" /tmp/proton-cli
|
||
|
|
--setenv HOME "$HOME" --setenv PATH /usr/bin:/bin
|
||
|
|
--setenv PROTON_PROFILE "$NODE"
|
||
|
|
--setenv PROTON_NO_INPUT 1
|
||
|
|
--unsetenv DISPLAY --unsetenv WAYLAND_DISPLAY --unsetenv XDG_RUNTIME_DIR)
|
||
|
|
|
||
|
|
exec sudo -n "$NETVM_BIN/netvm-enter.sh" "$NODE" "$(id -u)" "$(id -g)" "$HOME" \
|
||
|
|
-- "${BWRAP[@]}" -- /tmp/proton-cli "$@"
|