#!/bin/bash

## Copyright (C) 2026 - 2026 ENCRYPTED SUPPORT LLC <adrelanos@whonix.org>
## See the file COPYING for copying conditions.

## AI-Assisted

## Record sha512 of each built VirtualBox .ova as build evidence: write them to
## 'ova-sha512.txt' in the workspace (uploaded as its own artifact) and echo them
## to the job log. Kept as a ci/ script (github-actions-security.md rule 7) so this
## shell is shellcheck / 'bash -n' covered and runnable locally. The Whonix vbox
## dispatch is the only producer of .ova files in this lane.

set -o errexit
set -o nounset
set -o pipefail
set -o errtrace
shopt -s inherit_errexit
shopt -s shift_verbose
export LC_ALL=C

## Where docker/derivative-maker-docker-run bind-mounts binary_build_folder_dist
## on the runner; the .ova(s) land under it.
binary_mnt="/home/runner/binary_mnt"

out="ova-sha512.txt"

## Read-only over the build output; write the evidence into the workspace, not
## next to the (in-container-uid-owned) .ova, so no chown dance is needed.
ova_list=()
while IFS= read -r ova_item; do
   ova_list+=("${ova_item}")
done < <(find "${binary_mnt}" -type f -name '*.ova' | sort)

if [ "${#ova_list[@]}" -eq 0 ]; then
   printf '%s: no .ova found under %s\n' "${BASH_SOURCE[0]}" "${binary_mnt}" >&2
   exit 1
fi

true > "${out}"
for ova_item in "${ova_list[@]}"; do
   sha512sum -- "${ova_item}" | tee -a -- "${out}"
done

printf '%s: recorded sha512 for %d .ova file(s) in %s\n' \
   "${BASH_SOURCE[0]}" "${#ova_list[@]}" "${out}"
