#!/bin/bash

## Copyright (C) 2026 - 2026 ENCRYPTED SUPPORT LLC <adrelanos@whonix.org>
## See the file COPYING for copying conditions.

## AI-Assisted

set -o errexit
set -o nounset
set -o pipefail
set -o errtrace
shopt -s inherit_errexit
shopt -s shift_verbose
export LC_ALL=C

if [ "${CI:-}" != "true" ]; then
   printf '%s\n' "${BASH_SOURCE[0]}: refusing to run outside CI (CI != \"true\")" >&2
   exit 1
fi

## Every dry-run.d step (and the build they drive) inherits this. 100_install
## apt-installs packages whose postinst prompts via debconf (pbuilder asks for a
## mirror). With a controlling terminal present -- as when the container is run
## with a pty (docker run --tty) -- debconf's Readline frontend BLOCKS forever
## waiting for input that never comes, hanging the whole lane. CI's 'docker exec'
## happens to have no pty so it dodged this, but relying on that is fragile;
## pin the frontend non-interactive so the outcome does not depend on a tty.
export DEBIAN_FRONTEND=noninteractive

cd -- "$(dirname -- "$(readlink -f -- "${BASH_SOURCE[0]}")")/.."

## Steps must be named [a-zA-Z0-9_-] only: run-parts skips anything else, so a
## step called '500_compare.sh' would silently not run.
##
## Signing opt-in (dist_build_sign_and_tag defaults off) is set per step via the
## 'env VAR=val' prefix on each run-as-user hand-off, NOT exported here: run-as-user
## drops privileges with 'sudo --preserve-env=PATH', which strips everything but
## PATH, so an export here would not survive into 200_sign-and-tag or the build.
run-parts --exit-on-error --verbose -- ./ci/dry-run.d
