# Copyright 2020-2026 Gentoo Authors
# Distributed under the terms of the GNU General Public License v2

EAPI=8

inherit unpacker systemd bash-completion-r1

DESCRIPTION="Witen Warden log-tailing jailer (prebuilt binary)"
HOMEPAGE="https://www.witenlabs.com"
SRC_URI="
	https://www.witenlabs.com/api/releases/warden/artifacts/witen-warden-${PV}-linux-amd64-glibc.tar.gz
	https://www.witenlabs.com/api/releases/warden/artifacts/witen-warden_${PV}-1_amd64.deb
"

S="${WORKDIR}"

LICENSE="all-rights-reserved"
SLOT="0"
KEYWORDS="-* ~amd64"
IUSE="bash-completion iptables"
RESTRICT="bindist mirror strip"

QA_PREBUILT="usr/bin/warden"

RDEPEND="
	app-misc/ca-certificates
	net-firewall/nftables
	sys-apps/acl
	virtual/logger
	bash-completion? ( app-shells/bash-completion )
	iptables? ( net-firewall/iptables )
"

pkg_setup() {
	if ! getent group witen-warden >/dev/null; then
		groupadd --system witen-warden || die "failed to create group witen-warden"
	fi
	if ! getent passwd witen-warden >/dev/null; then
		useradd \
			--system \
			--gid witen-warden \
			--home-dir /var/lib/witen \
			--create-home \
			--shell /sbin/nologin \
			witen-warden \
			|| die "failed to create user witen-warden"
	fi
}

src_install() {
	# unpacker extracts the deb and does not run its maintainer scripts.
	# The portable install.sh is not executed.

	exeinto /usr/bin
	doexe usr/bin/warden

	exeinto /usr/libexec/witen-warden
	doexe \
		usr/libexec/witen-warden/prepare-state \
		usr/libexec/witen-warden/prepare-log-access \
		usr/libexec/witen-warden/smoke-journal

	systemd_dounit usr/lib/systemd/system/witen-warden.service
	grep -q 'ExecStart=/usr/bin/warden' \
		usr/lib/systemd/system/witen-warden.service \
		|| die "systemd unit does not start /usr/bin/warden"

	local portable="${WORKDIR}/witen-warden-${PV}-linux-amd64-glibc"
	sed -e 's|/usr/local/bin/warden|/usr/bin/warden|g' \
		"${portable}/witen-warden.openrc" > "${T}/witen-warden.openrc" || die
	sed -e 's|/usr/local/bin/warden|/usr/bin/warden|g' \
		"${portable}/witen-warden.confd" > "${T}/witen-warden.confd" || die
	grep -q '/usr/bin/warden' "${T}/witen-warden.openrc" \
		|| die "OpenRC command path was not rewritten"
	grep -q '/usr/bin/warden' "${T}/witen-warden.confd" \
		|| die "conf.d command path was not rewritten"
	if grep -q '/usr/local/bin/warden' "${T}/witen-warden.openrc" \
		"${T}/witen-warden.confd"; then
		die "OpenRC files still name /usr/local/bin/warden"
	fi
	newinitd "${T}/witen-warden.openrc" witen-warden
	newconfd "${T}/witen-warden.confd" witen-warden

	insinto /etc/logrotate.d
	newins "${portable}/witen-warden.logrotate" witen-warden

	# Mode 0640, group witen-warden. pkg_postinst repeats that when this
	# merge created the file; config-protect leaves an operator copy alone.
	insinto /etc/witen
	insopts -m0640
	doins etc/witen/warden.toml
	fowners root:witen-warden /etc/witen/warden.toml
	insopts -m0644

	if use bash-completion; then
		newbashcomp usr/share/bash-completion/completions/warden warden
	fi

	doman \
		usr/share/man/man8/warden.8 \
		usr/share/man/man5/warden.toml.5

	local callers
	for callers in \
		"${portable}/local-callers.md" \
		"${WORKDIR}/usr/share/doc/witen-warden/local-callers.md"
	do
		if [[ -f ${callers} ]]; then
			dodoc "${callers}"
			break
		fi
	done
}

pkg_postinst() {
	local cfg="${EROOT}/etc/witen/warden.toml"
	local pending=( "${EROOT}"/etc/witen/._cfg????_warden.toml )
	if [[ -f ${cfg} && ! -e ${pending[0]} && -z ${REPLACING_VERSIONS} ]]; then
		chmod 0640 "${cfg}" || die "chmod ${cfg}"
		chgrp witen-warden "${cfg}" || die "chgrp ${cfg}"
	fi
}