protonfs 
Sync a local directory tree with Proton Drive, via the official Proton Drive CLI, with conflict-aware push/pull and a local sync manifest.
Originally built to replace git-lfs as the storage layer for large, write-once simulation output — data that doesn't need version history, just somewhere durable to live and a way to fetch it back on demand.
The command surface (setup, status, ls, push, pull, rm, restore,
refresh, install-drive, auth) is implemented — see src/protonfs/cli.py.
Requirements
- Python >= 3.9
- The
proton-driveCLI binary — install it withprotonfs install-drive(below), or supply your own onPATH/ viaPROTONFS_DRIVE_BIN.
Install
pip install protonfs
protonfs install-drive # downloads + SHA-512-verifies the official proton-drive binary
protonfs auth login # opens a URL to authenticate (passthrough to proton-drive)
install-drive detects your platform (linux-x64/arm64, macOS x64/arm64 — all
checksum-pinned), requires AVX2 for the linux-x64 prebuilt (with an instructive
fallback otherwise), and never installs a binary whose SHA-512 does not match
the pinned checksum. Override the version with PROTONFS_DRIVE_VERSION and the
expected checksum with PROTONFS_DRIVE_SHA512. On Windows, use WSL — native
Windows is out of scope for 1.0.
Headless Linux (SSH, no desktop)
proton-drive keeps its session in the OS keyring, which on Linux means the
freedesktop Secret Service reached over the D-Bus session bus. An SSH login
has neither, which produces two failures that look like bugs in Proton Drive but
are really a missing environment:
Cannot autolaunch D-Bus without X11 $DISPLAY # no session bus at all
Cannot create an item in a locked collection # bus exists; the keyring is sealed
The second one is the nastier of the two: if the machine has ever had a graphical
login, ~/.local/share/keyrings/login.keyring exists, is the default collection,
and is locked with a password you cannot type over SSH — so auth login completes
the whole browser flow and only then fails to save the session.
protonfs handles both for you. Every command that shells out to proton-drive
first reuses (or starts, and caches) a session bus, and runs gnome-keyring-daemon
against a protonfs-owned keyring directory so it never has to unlock the sealed
system keyring. To check a host:
protonfs doctor # binary, session bus, Secret Service, and a real keyring write test
protonfs doctor --fix # ...and repair what it can
Requires dbus-launch, gnome-keyring-daemon and gdbus (packages dbus/dbus-x11,
gnome-keyring, glib2). No root needed. To run the proton-drive binary by hand in
the same environment, use eval "$(protonfs shell-init)".
Escape hatches: PROTONFS_KEYRING_PASSWORD supplies your own keyring password
instead of the generated one, and PROTONFS_NO_KEYRING_BOOTSTRAP=1 turns all of
this off if you'd rather manage the environment yourself.
Scoping what gets synced
.protonfs/ignore is a denylist in gitignore syntax, scoped to a repo and
independent of its own .gitignore — patterns like *.tmp or core.* are
excluded from every push/pull/refresh/status/ls.
Syncing only matching files
Sometimes you want the opposite: sync only files of certain types (e.g. only
simulation dumps, ignoring notes/scratch/logs). Add an allowlist at
.protonfs/include, in the same gitignore syntax:
# .protonfs/include
*.ev
*.sink
*_[0-9][0-9][0-9][0-9][0-9]
When .protonfs/include exists and has at least one active (non-blank,
non-comment) line, a file is synced only if it matches one of its patterns —
and still not matched by .protonfs/ignore, which always wins over include.
If include is absent, or every line in it is blank/commented out, behaviour
is unchanged: everything not matched by ignore is synced.
Patterns are plain gitignore file patterns, matched only against file paths.
You don't need !*/ or dir/** tricks here — directories are always
descended into regardless of include/ignore, so a plain *.ev reaches files
at any depth.
If you'd rather not add a second file, the same "only these files" behaviour
can be expressed with .protonfs/ignore alone, but it needs a double-negation
recipe and has two sharp edges:
# .protonfs/ignore -- sync only *.ev/*.sink and files ending in a 5-digit run number
*
!*/
!*_[0-9][0-9][0-9][0-9][0-9]
!*.ev
!*.sink
*mload*/**
!*/is mandatory: once a parent directory is excluded, a later re-include pattern (like!*.ev) cannot resurrect files under it — gitignore semantics never descend into an already-excluded directory to re-evaluate its contents.- to exclude a whole subtree again (here, anything under a
*mload*directory) you must writedir/**, notdir/— a trailing-slash directory pattern does not match the files beneath it when tested against file paths the way protonfs's matcher does.
.protonfs/include avoids both pitfalls, which is why it exists as a
separate first-class file rather than only being achievable via ignore.
Releasing (maintainers)
See CHANGELOG.md for release history and upgrade notes. To
upgrade an installation: pip install --upgrade protonfs, then protonfs upgrade to bring the proton-drive binary and any repo state current (docs:
Upgrading).
Merges to main auto-tag a release, but only after the full test matrix passes
with an 80% coverage floor on the exact commit being tagged (auto-release.yml
calls the CI workflow before creating the tag). Before milestone or manual tags,
also run the live suite against a disposable Drive directory — it exercises
real uploads/downloads that CI never can:
PROTONFS_TEST_REMOTE=/my-files/test .github/scripts/release_gate.sh
License
PolyForm Noncommercial 1.0.0 — free for noncommercial use with attribution; contact the author for commercial use.
Release files for protonfs 1.0.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| protonfs-1.0.2.tar.gz | 175.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| protonfs-1.0.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 262.0 kB
Release files / protonfs-1.0.2.tar.gz
| Download URL | protonfs-1.0.2.tar.gz |
|---|---|
| Size | 175.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a30ca29a2a0d781a8109d4c7b5e02e73fcffdacd18ebf3b7b3f5d8a16bf545eb
|
|
BLAKE2b-256 checksum How to use checksums |
e7753171b99176674505b312a87a93faeff8b9d590195ac9b8b98b1d5f90a9a6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Release files / protonfs-1.0.2-py3-none-any.whl
| Download URL | protonfs-1.0.2-py3-none-any.whl |
|---|---|
| Size | 86.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
41e2d80a5912115bc5a8227f6653196a5c8a348ba2de681ba300399cbb414264
|
|
BLAKE2b-256 checksum How to use checksums |
ae229b782c1e50e2054d950f22293b770f72af975ce4ed7f1f531d7e0058bab3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|