#!/usr/bin/env bash
set -euo pipefail
version='20260928-05'
prefix="/opt/vcoder-desktop-alpha/$version"
if [[ "${1:-}" != '--install-system' ]]; then
  printf '%s\n' 'Linux desktop alpha requires an X11 session, Python 3, xdotool, curl and unzip.'
  printf '%s\n' 'Use the reviewed installer with sudo and --install-system to install root-owned runtime files and the standard Electron sandbox.'
  printf '%s\n' "Then run $prefix/start.sh as your normal desktop user. Wayland and root desktop sessions are unsupported."
  exit 0
fi
[[ "$EUID" == 0 ]] || { echo 'System installation requires administrator permission.' >&2; exit 1; }
[[ "$(uname -m)" == x86_64 ]] || { echo 'Desktop alpha requires x86_64 Linux.' >&2; exit 1; }
for command in curl unzip sha256sum python3 xdotool; do command -v "$command" >/dev/null || { echo "Missing prerequisite: $command" >&2; exit 1; }; done
payload_sha='36fca4607463a6e3bea9d54c2113b98fabcc3ee9d2bdc967190150b8cf13d78b'
runtime_sha='9cea932df41cb6e68122ecd32f814db5a7544592f3091983b959f4f7e0d6fd88'
if [[ -f "$prefix/verified-release.json" ]]; then
  python3 - "$prefix/verified-release.json" "$payload_sha" "$runtime_sha" <<'PY'
import json,sys
r=json.load(open(sys.argv[1]))
assert r['payloadSha256']==sys.argv[2] and r['runtimeSha256']==sys.argv[3], 'Installed release differs'
PY
else
  [[ ! -e "$prefix" ]] || { echo 'Incomplete install exists; choose a fresh version.' >&2; exit 1; }
  stage=$(mktemp -d /var/tmp/vcoder-desktop-install.XXXXXXXX)
  chmod 700 "$stage"
  curl --fail --location --proto '=https' --tlsv1.2 'https://getvcoder.com/downloads/desktop-alpha/vcoder-desktop-linux-x64-20260928-05.zip' -o "$stage/app.zip"
  printf '%s  %s\n' "$payload_sha" "$stage/app.zip" | sha256sum -c -
  curl --fail --location --proto '=https' --tlsv1.2 'https://github.com/electron/electron/releases/download/v44.1.0/electron-v44.1.0-linux-x64.zip' -o "$stage/runtime.zip"
  printf '%s  %s\n' "$runtime_sha" "$stage/runtime.zip" | sha256sum -c -
  mkdir "$stage/release" "$stage/release/runtime"
  unzip -q "$stage/app.zip" -d "$stage/release"
  unzip -q "$stage/runtime.zip" -d "$stage/release/runtime"
  cat > "$stage/release/start.sh" <<'RUN'
#!/usr/bin/env bash
set -euo pipefail
[[ "$EUID" != 0 ]] || { echo 'Run the host as a normal desktop user.' >&2; exit 1; }
[[ "${XDG_SESSION_TYPE:-x11}" != wayland && -n "${DISPLAY:-}" ]] || { echo 'Desktop alpha requires an active X11 session; Wayland is unsupported.' >&2; exit 1; }
for command in python3 xdotool; do command -v "$command" >/dev/null || { echo "Missing prerequisite: $command" >&2; exit 1; }; done
base=$(cd -- "$(dirname -- "$0")" && pwd)
unset ELECTRON_RUN_AS_NODE
exec "$base/runtime/electron" "$base/app"
RUN
  python3 - "$stage/release/verified-release.json" "$version" "$payload_sha" "$runtime_sha" <<'PY'
import json,sys
json.dump(dict(version=sys.argv[2],payloadSha256=sys.argv[3],runtimeSha256=sys.argv[4]),open(sys.argv[1],'w'),indent=2)
PY
  chown -R root:root "$stage/release"
  chmod -R a+rX,go-w "$stage/release"
  chmod 755 "$stage/release/runtime/electron" "$stage/release/start.sh"
  chmod 4755 "$stage/release/runtime/chrome-sandbox"
  install -d -m 755 /opt/vcoder-desktop-alpha
  mv "$stage/release" "$prefix"
  rm "$stage/app.zip" "$stage/runtime.zip"
  rmdir "$stage"
fi
printf '%s\n' "Installed desktop alpha: $prefix/start.sh"
printf '%s\n' 'Start it as your normal X11 desktop user, choose a display and Share, then approve your browser. No service, capture or remote access is enabled by installation.'
