#!/usr/bin/env bash
# Run as root on the local test host, after importing the bundled scanner archive.
set -euo pipefail
out="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)"
engine=(podman --root "$out/storage" --runroot /tmp/devsecops-test-runroot --storage-driver vfs)
image=localhost/devsecops/scanner:20260909
"${engine[@]}" image inspect "$image" > "$out/scanner-inspect.json"
"${engine[@]}" run --rm --pull=never --network=none "$image" \
  bash /opt/devsecops/tests/test-adapter.sh > "$out/container-adapter.log" 2>&1
# A disposable container hosts both ZAP and the loopback-only test HTTP server.
# Keep it until reports have been copied, then remove only this test container.
name="devsecops-zap-test-$$"
trap '"${engine[@]}" rm -f "$name" >/dev/null 2>&1 || true' EXIT
"${engine[@]}" create --name "$name" --pull=never --network=none "$image" \
  bash /opt/devsecops/tests/test-zap.sh > "$out/zap-container-id.txt"
"${engine[@]}" inspect "$name" > "$out/zap-container-inspect.json"
"${engine[@]}" start --attach "$name" > "$out/zap-localhost.log" 2>&1
code="$("${engine[@]}" inspect --format '{{.State.ExitCode}}' "$name")"
mkdir -p "$out/zap-reports"
"${engine[@]}" cp "$name:/zap/wrk/." "$out/zap-reports/"
[[ "$code" == 0 ]] || { echo "ZAP test failed with exit $code" >&2; exit 1; }
echo 'PASS: offline container adapter and ZAP localhost test'
