diff --git a/Dockerfile b/Dockerfile index 6b5d367..db7da54 100644 --- a/Dockerfile +++ b/Dockerfile @@ -35,9 +35,12 @@ COPY gpgparams entrypoint.sh /protonmail/ COPY scripts/generate_new_certs.sh /root/generate_new_certs.sh WORKDIR /protonmail/ -# Copy protonmail -COPY --from=build /build/proton-bridge/bridge /usr/bin/ -COPY --from=build /build/proton-bridge/proton-bridge /usr/bin/ -COPY --from=build /build/proton-bridge/vault-editor /usr/bin/ +# Copy Proton Mail Bridge. +# Important: use the patched nogui `bridge` binary as both executable names. +# The upstream `proton-bridge` launcher can auto-update into an official binary +# that still binds IMAP/SMTP to 127.0.0.1, bypassing our 0.0.0.0 patch. +COPY --from=build /build/proton-bridge/bridge /usr/bin/bridge +COPY --from=build /build/proton-bridge/bridge /usr/bin/proton-bridge +COPY --from=build /build/proton-bridge/vault-editor /usr/bin/vault-editor ENTRYPOINT ["bash", "/protonmail/entrypoint.sh"] diff --git a/entrypoint.sh b/entrypoint.sh index 93584e6..ec40b7c 100644 --- a/entrypoint.sh +++ b/entrypoint.sh @@ -18,20 +18,29 @@ if [ ! -d "/root/.password-store" ]; then pass init "$KEY" fi +# Avoid launching Proton's auto-updated upstream binary from the persisted +# /root volume. Those official binaries bind IMAP/SMTP to 127.0.0.1. This image +# deliberately runs the patched nogui binary from /usr/bin, built with host +# constant 0.0.0.0. +rm -rf /root/.local/share/protonmail/bridge-v3/updates + +BRIDGE_BIN=/usr/bin/bridge + # Initialize if [[ "$1" == "init" ]]; then # Kill the other instance as only one can be running at a time. # This allows users to run entrypoint init inside a running conainter # which is useful in a k8s environment. # || true to make sure this would not fail in case there is no running instance. - pkill protonmail-bridge || true + pkill bridge || true + pkill proton-bridge || true # Run any ProtonMail Bridge Command - Login - proton-bridge --cli "$@" + "$BRIDGE_BIN" --cli "$@" else # Start ProtonMail Bridge # Fake a terminal, so it does not quit because of EOF... rm -f faketty mkfifo faketty - cat faketty | proton-bridge --cli "$@" + cat faketty | "$BRIDGE_BIN" --cli "$@" fi