#!/bin/bash

## Copyright (C) 2012 - 2025 ENCRYPTED SUPPORT LLC <adrelanos@whonix.org>
## See the file COPYING for copying conditions.

## example usage:
## Requires local repository already created.
## sudo dm-install-from-local-repository --target root --flavor whonix-gateway --build

set -x
set -o errexit
set -o nounset
set -o pipefail
set -o errtrace
shopt -s inherit_errexit
shopt -s shift_verbose
export LC_ALL=C

true "INFO: Currently running script: ${BASH_SOURCE[0]} $*"

MYDIR="$( cd -- "$( dirname -- "${BASH_SOURCE[0]}" )" && pwd )"
cd -- "${MYDIR}"

## XXX: hardcoded path
source "${HOME}/derivative-maker/help-steps/pre"
source "${HOME}/derivative-maker/help-steps/variables"

main() {
   trap "exception_handler_unchroot_unmount" ERR INT TERM

   ## Fail fast, before any apt work: when 'pkg' is not overridden the meta-package
   ## name is derived from the qubes axis below, and 'dist_build_qubes' is an
   ## operator-supplied toggle that nothing in the build sets.
   if [ "${pkg:-}" = "" ]; then
      case "${dist_build_qubes:-}" in
         true|false)
            true
            ;;
         *)
            error "${BASH_SOURCE[0]}: dist_build_qubes must be set to 'true' or 'false' (got: '${dist_build_qubes:-}', empty means unset). It selects the qubes vs nonqubes meta-package. Export it, or pass an explicit 'pkg'. Please report this bug if unexpected!"
            ;;
      esac
   fi

   ## Move existing /etc/apt/sources.list out of the way.
   if ! test -e /etc/apt/sources.list.backup ; then
      if test -e /etc/apt/sources.list ; then
         mv -- /etc/apt/sources.list /etc/apt/sources.list.backup || true
      fi
   fi

   ## This file doesn't include Whonix's APT repository.
   cp -- "${source_code_folder_dist}/packages/anon-apt-sources-list/etc/apt/sources.list.d/debian.sources" "${CHROOT_FOLDER}/etc/apt/sources.list.d/debian.sources"
   chmod o+r -- "${CHROOT_FOLDER}/etc/apt/sources.list.d/debian.sources"

   "${dist_source_help_steps_folder}/create-local-temp-apt-repo" "$@"

   ## Reading local repository containing Whonix's packages.
   chroot_run apt-get "${DIST_APTGETOPT[@]}" ${apt_sourcelist_empty} ${apt_sourceparts} -o APT::Get::List-Cleanup="0" update

   if [ "${pkg:-}" = "" ]; then
      ## Compose the canonical meta-package name from the flavor and qubes-ness:
      ##   whonix-<gateway|workstation>-<qubes|nonqubes>-<cli|gui-lxqt>.
      local whonix_role whonix_ui whonix_virt
      case "${dist_build_flavor}" in
         whonix-gateway-*)
            whonix_role="gateway"
            ;;
         whonix-workstation-*)
            whonix_role="workstation"
            ;;
         *)
            error "${BASH_SOURCE[0]}: flavor '${dist_build_flavor}' is neither whonix-gateway-* nor whonix-workstation-*. Please report this bug!"
            ;;
      esac
      case "${dist_build_flavor}" in
         *-cli)
            whonix_ui="cli"
            ;;
         *-lxqt)
            whonix_ui="gui-lxqt"
            ;;
         *)
            error "${BASH_SOURCE[0]}: flavor '${dist_build_flavor}' has no recognised UI suffix (-cli or -lxqt). Please report this bug!"
            ;;
      esac
      if [ "${dist_build_qubes}" = "true" ]; then
         whonix_virt="qubes"
      else
         ## 'vm', not 'nonqubes'. 'nonqubes' is a "partially shared node" in our
         ## metapackage structure, see
         ## https://www.kicksecure.com/wiki/Dev/Metapackages. It isn't meant to
         ## be installed or upgraded directly.
         ##
         ## TODO: Once Whonix-Host becomes a thing, or if we start supporting
         ## Kicksecure in this script, we will need to take "baremetal" into
         ## account.
         whonix_virt="vm"
      fi
      pkg="whonix-${whonix_role}-${whonix_virt}-${whonix_ui}"
   fi

   chroot_run apt-get "${DIST_APTGETOPT[@]}" ${apt_sourcelist_empty} ${apt_sourceparts} --yes install ${pkg}

   #chroot_run apt-get "${DIST_APTGETOPT[@]}" $apt_sourcelist_empty $apt_sourceparts -f install

   "${dist_source_help_steps_folder}/remove-local-temp-apt-repo" "$@"

   ## Forget about local repository containing Whonix's packages.
   chroot_run apt-get --no-download --list-cleanup update
}

main "$@"
