#!/bin/bash
# WolfViewer — add the Wolf Territories package repository and install WolfViewer.
#
#   sudo bash -c "$(curl -fsSL https://wolf-grid.com/linux/setup.sh)"
#
# After this, your system's normal updater (Software Updater, Discover, dnf, zypper, pacman -Syu)
# keeps WolfViewer up to date. Supported: Debian, Ubuntu, Mint and other apt systems; Fedora,
# RHEL/Rocky/Alma (dnf); openSUSE (zypper); Arch, Manjaro, EndeavourOS (pacman). 64-bit x86 only.
#
# What it changes, and nothing else:
#   apt:    /etc/apt/keyrings/wolfviewer.gpg, /etc/apt/sources.list.d/wolfviewer.sources
#   dnf:    /etc/yum.repos.d/wolfviewer.repo
#   zypper: the repository "wolfviewer" and its key
#   pacman: the key in pacman's keyring, a [wolfviewer] section at the end of /etc/pacman.conf
# Signing key fingerprint: 462CC46A33ECC9B1E0F40E8891F41EF4CB1C45A2
set -euo pipefail

BASE="https://wolf-grid.com/linux"
FPR="462CC46A33ECC9B1E0F40E8891F41EF4CB1C45A2"

say() { printf '\033[1m%s\033[0m\n' "$*"; }
die() { printf '\033[31m%s\033[0m\n' "$*" >&2; exit 1; }

[ "$(id -u)" = 0 ] || die "Run this as root: sudo bash -c \"\$(curl -fsSL $BASE/setup.sh)\""
[ "$(uname -m)" = x86_64 ] || die "WolfViewer is built for 64-bit x86 (x86_64) only; this machine is $(uname -m)."
command -v curl >/dev/null || die "curl is needed."

. /etc/os-release
FAMILY=""
for id in ${ID:-} ${ID_LIKE:-}; do
    case "$id" in
        debian|ubuntu)                         FAMILY=apt; break ;;
        fedora|rhel|centos|rocky|almalinux)    FAMILY=dnf; break ;;
        opensuse*|suse|sles)                   FAMILY=zypper; break ;;
        arch|archlinux|manjaro|endeavouros)    FAMILY=pacman; break ;;
    esac
done
[ -n "$FAMILY" ] || die "No package repository for ${PRETTY_NAME:-this system} yet. Use the download from https://www.wolf-grid.com/index.php?f=osv instead."
say "Setting up WolfViewer for ${PRETTY_NAME:-$ID} ($FAMILY)"

TMP="$(mktemp -d)"; trap 'rm -rf "$TMP"' EXIT
curl -fsSL "$BASE/wolfviewer-archive-key.asc" -o "$TMP/key.asc"
# The key must be the one this script names, whatever the server sent.
got="$(gpg --batch --with-colons --show-keys "$TMP/key.asc" 2>/dev/null | awk -F: '/^fpr/{print $10; exit}')" || true
if command -v gpg >/dev/null && [ "$got" != "$FPR" ]; then
    die "The downloaded signing key is not WolfViewer's ($got). Nothing was changed."
fi

case "$FAMILY" in
apt)
    install -d -m 0755 /etc/apt/keyrings
    if command -v gpg >/dev/null; then
        # From the key just checked against the fingerprint above.
        gpg --batch --yes --dearmor -o /etc/apt/keyrings/wolfviewer.gpg "$TMP/key.asc"
    else
        curl -fsSL "$BASE/wolfviewer-archive-keyring.gpg" -o /etc/apt/keyrings/wolfviewer.gpg
    fi
    chmod 0644 /etc/apt/keyrings/wolfviewer.gpg
    cat > /etc/apt/sources.list.d/wolfviewer.sources <<EOF
Types: deb
URIs: $BASE/apt
Suites: stable
Components: main
Architectures: amd64
Signed-By: /etc/apt/keyrings/wolfviewer.gpg
EOF
    apt-get update
    apt-get install -y wolfviewer
    ;;
dnf)
    curl -fsSL "$BASE/wolfviewer.repo" -o /etc/yum.repos.d/wolfviewer.repo
    rpm --import "$TMP/key.asc"
    dnf install -y wolfviewer
    ;;
zypper)
    rpm --import "$TMP/key.asc"
    zypper --non-interactive removerepo wolfviewer >/dev/null 2>&1 || true
    zypper --non-interactive addrepo --refresh --check "$BASE/rpm" wolfviewer
    zypper --non-interactive --gpg-auto-import-keys refresh wolfviewer
    zypper --non-interactive install wolfviewer
    ;;
pacman)
    pacman-key --add "$TMP/key.asc"
    pacman-key --lsign-key "$FPR"
    if ! grep -q '^\[wolfviewer\]' /etc/pacman.conf; then
        cat >> /etc/pacman.conf <<'EOF'

[wolfviewer]
SigLevel = Required DatabaseRequired
Server = https://wolf-grid.com/linux/arch/$arch
EOF
    fi
    # A full upgrade, not -Sy alone: Arch does not support partial upgrades.
    pacman -Syu --needed wolfviewer
    ;;
esac

say "WolfViewer is installed. Start it from your applications menu, or run: wolfviewer"
say "Updates now come with your system's other updates."
