#!/usr/bin/env bash
# preflight.sh: prove the container network mode leaks nothing BEFORE any subject runs.
# A real curl, in a container with the probe's network flags, must fail to reach a public IP.
# Writes $PROBE_RUNS/preflight.txt. Exit 0 only if every attempt failed.
set -uo pipefail
KIT=$(cd "$(dirname "$0")" && pwd)
RUNS=${PROBE_RUNS:-$KIT/runs}
CURL_IMAGE=${PROBE_CURL_IMAGE:-curlimages/curl:latest}
mkdir -p "$RUNS"
{
  echo "preflight at $(date -u +%FT%TZ) on $(hostname -s); image $CURL_IMAGE"
  ok=1
  for url in https://1.1.1.1/ https://20.184.175.9/ https://mobile.events.data.microsoft.com/; do
    out=$(docker run --rm --network none --cap-drop ALL "$CURL_IMAGE" -sS -m 5 -o /dev/null "$url" 2>&1)
    rc=$?
    echo "curl $url -> exit $rc: $out"
    [ $rc -ne 0 ] || ok=0
  done
  [ $ok -eq 1 ] && echo "PASS: nothing reachable" || echo "FAIL: something was reachable"
} | tee "$RUNS/preflight.txt"
grep -q '^PASS' "$RUNS/preflight.txt"
