#!/bin/bash

## Copyright (C) 2012 - 2025 ENCRYPTED SUPPORT LLC <adrelanos@whonix.org>
## See the file COPYING for copying conditions.

set -x
set -o errexit
set -o nounset
set -o pipefail
set -o errtrace
shopt -s inherit_errexit
shopt -s shift_verbose
export LC_ALL=C

true "INFO: Currently running script: ${BASH_SOURCE[0]} $*"

MYDIR="$( cd -- "$( dirname -- "${BASH_SOURCE[0]}" )" && pwd )"
cd -- "${MYDIR}"

dist_build_source_run="true"

## XXX: hardcoded path
source "${HOME}/derivative-maker/help-steps/pre"
source "${HOME}/derivative-maker/help-steps/variables"

# shellcheck source=../../../helper-scripts/usr/libexec/helper-scripts/has.bsh
source "${HELPER_SCRIPTS_PATH:-}"/usr/libexec/helper-scripts/has.bsh

if [ "$(id -u)" = "0" ]; then
   true "ERROR: Do not run this as root!"
   exit 1
fi

sanity_tests() {
   has signify-openbsd
   test -f "${signify_public_key}"
   test -f "${signify_private_key}"

   has rsstail

   test -n "${DEBEMAIL:-}"

   "${dist_source_help_steps_folder}/signing-key-test" "$@"
}

sign_and_verify_openpgp() {
   local base_name detached_signature clearsigned_file
   test -f "${full_path_to_canary_txt}"
   base_name="$(basename -- "${full_path_to_canary_txt}")"

   detached_signature="${binary_build_folder_dist}/canary/canary.txt.asc"
   clearsigned_file="${binary_build_folder_dist}/canary/canary.txt.clearsign.asc"

   safe-rm -f -- "${detached_signature}"
   safe-rm -f -- "${clearsigned_file}"

   ## '--signature-notation "file@name"':
   ## OpenPGP signatures do not authenticate filenames by default, therefore add
   ## the name of the file as a OpenPGP notation so at least users that look
   ## at OpenPGP notations have a chance to detect if file names have been
   ## tampered with.

   sq sign --signature-notation "file@name" "${base_name}" --signer-email "${DEBEMAIL}" --signature-file="${detached_signature}" -- "${full_path_to_canary_txt}"
   test -f "${detached_signature}"
   sq verify --signer-email "${DEBEMAIL}" --signature-file="${detached_signature}" -- "${full_path_to_canary_txt}"

   sq sign --signature-notation "file@name" "${base_name}" --signer-email "${DEBEMAIL}" --cleartext "${full_path_to_canary_txt}" | tee -- "${clearsigned_file}" >/dev/null
   test -f "${clearsigned_file}"
   ## Use '>/dev/null' to avoid output of full file content.
   sq verify --signer-email "${DEBEMAIL}" --cleartext -- "${clearsigned_file}" >/dev/null
}

sign_cmd_signify() {
   ## To create a key for signify-openbsd:
   ## as account "user"
   ## mkdir -p ~/.signify
   ## cd ~/.signify
   ## signify-openbsd -n -G -p keyname.pub -s keyname.sec -c "Firstname Lastname e-mail@address.org signify"

   ## https://forums.whonix.org/t/signify-openbsd/7842
   signify-openbsd -S -s "${signify_private_key}" -m "$1" -x "${1}${2}" ${3:-}
   ## Sanity test.
   test -f "${1}${2}"
}

verify_cmd_signify() {
   signify-openbsd -V -p "${signify_public_key}" -m "$1" -x "${1}${2}" ${3:-}
}

sanity_tests "$@"

if test -d "${binary_build_folder_dist}/canary" ; then
   safe-rm --recursive -- "${binary_build_folder_dist}/canary"
fi

mkdir --parents -- "${binary_build_folder_dist}/canary"

full_path_to_canary_txt="${binary_build_folder_dist}/canary/canary.txt"

cp -- "${dist_developer_meta_files_folder}/misc/canary-template.txt" "${full_path_to_canary_txt}"

proof_of_freshness_output="$(dm-proof-of-freshness-generator 2>&1)"
printf '%s\n' "${proof_of_freshness_output}" | tee --append -- "${full_path_to_canary_txt}"

cat -- "${full_path_to_canary_txt}"

sign_and_verify_openpgp

sign_cmd_signify "${full_path_to_canary_txt}" ".sig"
verify_cmd_signify "${full_path_to_canary_txt}" ".sig"

sign_cmd_signify "${full_path_to_canary_txt}" ".embed.sig" -e

signify-openbsd -V -e -p "${signify_public_key}" -x "${binary_build_folder_dist}/canary/canary.txt.embed.sig" -m "${binary_build_folder_dist}/canary/canary-unembed.txt"

diff -- "${full_path_to_canary_txt}" "${binary_build_folder_dist}/canary/canary-unembed.txt"

cat -- "${binary_build_folder_dist}/canary/canary.txt"

cp -- "${binary_build_folder_dist}/canary/canary.txt.asc" ~/sourcesown/canary/
cp -- "${binary_build_folder_dist}/canary/canary.txt" ~/sourcesown/canary/
cp -- "${binary_build_folder_dist}/canary/canary.txt.clearsign.asc" ~/sourcesown/canary/
cp -- "${binary_build_folder_dist}/canary/canary.txt.sig" ~/sourcesown/canary/
cp -- "${binary_build_folder_dist}/canary/canary.txt.embed.sig" ~/sourcesown/canary/

pushd -- ~/sourcesown/canary/
git add -A
git commit -a -m "update canary"
popd
