#!/bin/sh
set -eu
# The release builder replaces the public key and immutable version below.
VERSION='0.1.0'
PUBLIC_KEY='-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEUiZqTvGIbcYV3bJcwhrwGr7RTZEB
ZkyGbADijsAh+C9YSMvASfaqnt4nrqY4aFiUtEXr9ZQwgSKS/pUqBsFPlQ==
-----END PUBLIC KEY-----'
case "$PUBLIC_KEY" in @*|'') echo 'No signed ntfyx release is configured.' >&2; exit 1;; esac
case "$(uname -s)-$(uname -m)" in
 Darwin-arm64) platform=darwin-arm64;;
 Darwin-x86_64) platform=darwin-x64;;
 Linux-aarch64) platform=linux-arm64;;
 Linux-x86_64) platform=linux-x64;;
 *) echo 'Supported: macOS arm64/x64 and Linux glibc arm64/x64.' >&2; exit 1;;
esac
case "$platform" in linux-*) getconf GNU_LIBC_VERSION >/dev/null 2>&1 || { echo 'Linux glibc required; musl is not supported.' >&2; exit 1; };; esac
for tool in curl openssl mktemp awk sed; do command -v "$tool" >/dev/null || { echo "Missing dependency: $tool" >&2; exit 1; }; done
base="https://ntfyx.me/releases/$VERSION"
install_dir="${NTFYX_INSTALL_DIR:-$HOME/.local/bin}"
mkdir -p "$install_dir"
[ ! -L "$install_dir" ] || { echo 'Refusing a symlink install directory.' >&2; exit 1; }
target="$install_dir/ntfyx"
if [ -e "$target" ]; then
 [ ! -L "$target" ] && [ -f "$target" ] && [ -w "$target" ] || { echo 'Unsafe existing target.' >&2; exit 1; }
 old_metadata=$("$target" version --json)
 printf '%s' "$old_metadata" | grep -q '"application":"ntfyx"' || { echo 'Existing target does not identify as ntfyx.' >&2; exit 1; }
 old_version=$(printf '%s' "$old_metadata" | sed -n 's/.*"version":"\([0-9][0-9]*\.[0-9][0-9]*\.[0-9][0-9]*\)".*/\1/p')
 [ -n "$old_version" ] || { echo 'Existing target has no valid version.' >&2; exit 1; }
 awk -v old="$old_version" -v new="$VERSION" 'BEGIN {split(old,a,".");split(new,b,".");for(i=1;i<=3;i++){if(b[i]+0>a[i]+0)exit 0;if(b[i]+0<a[i]+0)exit 1}exit 0}' || { echo 'Refusing release downgrade.' >&2; exit 1; }
fi
stage=$(mktemp -d "$install_dir/.ntfyx-install.XXXXXX")
trap 'rm -rf "$stage"' EXIT HUP INT TERM
printf '%s\n' "$PUBLIC_KEY" > "$stage/release.pub"
curl --fail --silent --show-error --proto '=https' --tlsv1.2 "$base/SHA256SUMS" -o "$stage/SHA256SUMS"
curl --fail --silent --show-error --proto '=https' --tlsv1.2 "$base/SHA256SUMS.sig" -o "$stage/SHA256SUMS.sig"
openssl dgst -sha256 -verify "$stage/release.pub" -signature "$stage/SHA256SUMS.sig" "$stage/SHA256SUMS" >/dev/null || { echo 'Release signature invalid.' >&2; exit 1; }
artifact="ntfyx-$platform"
expected=$(awk -v name="$artifact" '$2==name {print $1}' "$stage/SHA256SUMS")
[ "${#expected}" -eq 64 ] || { echo 'Manifest has no unambiguous platform hash.' >&2; exit 1; }
curl --fail --silent --show-error --proto '=https' --tlsv1.2 "$base/$artifact" -o "$stage/ntfyx"
actual=$(openssl dgst -sha256 "$stage/ntfyx" | awk '{print $NF}')
[ "$actual" = "$expected" ] || { echo 'Binary checksum invalid.' >&2; exit 1; }
chmod 700 "$stage/ntfyx"
"$stage/ntfyx" version --json | grep -q '"application":"ntfyx"' || { echo 'Binary smoke test failed.' >&2; exit 1; }
if [ -L "$target.rollback" ] || [ -d "$target.rollback" ]; then echo 'Unsafe rollback path.' >&2; exit 1; fi
if [ -e "$target" ]; then cp -p "$target" "$stage/rollback"; mv "$stage/rollback" "$target.rollback"; fi
mv "$stage/ntfyx" "$target"
printf 'License and third-party notices: https://ntfyx.me/releases/%s/LICENSE and THIRD_PARTY_NOTICES.txt\n' "$VERSION"
printf 'Installed ntfyx %s at %s\nRun: %s connect\n' "$VERSION" "$target" "$target"
