#!/usr/bin/env bash
# 10-load.sh — run on EACH air-gapped RHEL 9.6 host that runs the Drone server
# or a Drone runner.
#
#   ./10-load.sh            # load into podman (default on RHEL)
#   ./10-load.sh docker     # load into Docker CE instead, if runners use it
#
# 1. verifies SHA256SUMS for the whole bundle
# 2. loads every image and checks its image ID against metadata/
# 3. tags the scanner image as :stable (the tag pipelines reference)
# 4. runs the scanner self-test and an image-archive scan with --network=none
#
# Podman and Docker keep SEPARATE image stores: load into the engine whose
# socket the Drone runner uses.
set -euo pipefail
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
source "$ROOT/config/versions.env"
source "$ROOT/config/scanner-image.env"

engine="${1:-podman}"
command -v "$engine" >/dev/null || { echo "$engine not found" >&2; exit 1; }

echo "== verifying bundle integrity =="
cd "$ROOT"
if [[ -f SHA256SUMS ]]; then
  sha256sum --check --quiet SHA256SUMS && echo "SHA256SUMS OK ($(wc -l < SHA256SUMS) files)"
else
  echo "SHA256SUMS not present (unpackaged tree); checking image archives only"
  for f in metadata/*-image.sha256; do sha256sum --check --quiet "$f"; done
  echo "image archive checksums OK"
fi

# load_image ARCHIVE TAG EXPECTED_ID
load_image() {
  local tar="$1" tag="$2" want="$3" have
  echo "-- $tar"
  "$engine" load -q -i "$tar" >/dev/null
  have="$("$engine" image inspect --format '{{.Id}}' "$tag")"
  have="sha256:${have#sha256:}"
  if [[ "$have" != "$want" ]]; then
    echo "FAIL: $tag has image ID $have, expected $want" >&2; exit 1
  fi
  echo "   $tag  OK ($want)"
}

echo "== loading images into $engine =="
while IFS=$'\t' read -r name archive tag _manifest image_id; do
  [[ "$name" == name ]] && continue
  load_image "$archive" "$tag" "$image_id"
done < metadata/images.tsv
load_image "$SCANNER_IMAGE_ARCHIVE" "$SCANNER_IMAGE" "$SCANNER_IMAGE_ID"

STABLE="$SCANNER_IMAGE_REPO:stable"
"$engine" tag "$SCANNER_IMAGE" "$STABLE"
echo "   tagged $STABLE -> $SCANNER_IMAGE"

echo "== scanner self-test (network disabled) =="
"$engine" run --rm --network=none "$STABLE" drone-scan smoke > metadata/load-smoke-test.log 2>&1 \
  || { tail -n 30 metadata/load-smoke-test.log; echo "FAIL: smoke test" >&2; exit 1; }
tail -n 1 metadata/load-smoke-test.log

echo "== image-archive scan (network disabled): UBI 9 minimal base =="
# Exercises Syft/Grype/Trivy on a docker-archive exactly as the trivy-image
# pipeline step does. The gate result is informational here.
"$engine" run --rm --network=none -v "$ROOT/images:/images:ro" "$STABLE" bash -c '
  set -e
  drone-scan sbom /images/ubi9-minimal-amd64.tar /tmp/r/image >/dev/null
  drone-scan grype /tmp/r/image >/dev/null
  drone-scan trivy-image /images/ubi9-minimal-amd64.tar /tmp/r >/dev/null 2>&1
  drone-scan gate /tmp/r | sed -n "/summary/,\$p" || true
' > metadata/load-image-scan.log 2>&1 \
  || { cat metadata/load-image-scan.log; echo "FAIL: image-archive scan" >&2; exit 1; }
grep -E 'packages|SECURITY GATE' metadata/load-image-scan.log || true
grep -q 'SECURITY GATE' metadata/load-image-scan.log || { cat metadata/load-image-scan.log; exit 1; }

echo
echo "PASS: all images loaded and verified; scanners work with no network."
echo "Next: scripts/20-install.sh server|runner   (or scripts/15-push-registry.sh)"
