#!/usr/bin/env bash
# deploy/publish-repo.sh — builds this repo's public source mirror: landing
# page + the repo as a dumb-HTTP-clonable bare mirror (plain static files —
# IPFS-friendly). Run by the ecosystem's assemble.sh, which serves it at
# https://<host>/<APP>/ (page) and https://<host>/<APP>.git (clone).
#
# Identity patterns for the leak scan are read from an untracked local file
# (IDPAT_FILE, default ~/.config/cod-sursa/idpat) — never write real identity
# strings into this script: it gets published.
set -euo pipefail
cd "$(dirname "$0")/.."
APP=rooms-kit # path under the host: <APP>.git
IDENT=rooms-kit # anonymous commit identity
IDPAT_FILE=${IDPAT_FILE:-"$HOME/.config/cod-sursa/idpat"}
OUT=deploy/.site
rm -rf "$OUT"
mkdir -p "$OUT"
# kit-specific gate: the committed dist must be exactly what a cold build of
# src/ produces (and must not carry the wrong WebRTC stack, nor a re-vendored
# copy of id-kit). check-vendor.sh is gone with src/vendor/: ardegazu-id-kit is a
# real sha-pinned npm dep now, compiled from its own sources off the classpath,
# so upstream drift is a pin bump rather than a hand-maintained copy.
deploy/check-dist.sh
cp site/index.html "$OUT/index.html"
# this ecosystem's assembler rsyncs only — each repo generates its own
# in-browser source browser (git.ardegazu.ro/<APP>/browse/)
python3 deploy/gen-browse.py --repo . --app "$APP" --out "$OUT/browse" \
--clone-url "https://git.ardegazu.ro/$APP.git"
# --no-local: a plain path clone hardlinks the whole objects dir, which can
# drag along unreachable/rewritten history — transport clone copies only
# what's reachable from refs
git clone --no-local --bare --quiet . "$OUT/$APP.git"
# Explode packs into loose objects: the IPFS gateway answers missing paths
# with a 200 fallback page, which makes git's loose-object probes error
# noisily before the pack fallback. All-loose means every requested path
# exists, so dumb-HTTP clones stay clean.
(
cd "$OUT/$APP.git"
for p in objects/pack/pack-*.pack; do
[ -e "$p" ] || continue
tmp=$(mktemp)
mv "$p" "$tmp"
rm -f "${p%.pack}".*
git unpack-objects -q < "$tmp"
rm -f "$tmp"
done
git update-server-info
)
# strip local-only noise from the published mirror
rm -rf "$OUT/$APP.git/hooks" "$OUT/$APP.git/config" 2>/dev/null || true
# ---- anonymity gate: refuse to build a mirror that leaks identity ----------
AUTHORS=$(git -C "$OUT/$APP.git" log --all --format='%an <%ae>%n%cn <%ce>' | sort -u)
if [ "$AUTHORS" != "$IDENT <$IDENT@noreply.local>" ]; then
echo "ABORT: non-anonymous commit identity in mirror:" >&2
echo "$AUTHORS" >&2
exit 1
fi
if git -C "$OUT/$APP.git" ls-tree -r --name-only HEAD | grep -q '\.site'; then
echo "ABORT: nested site build committed into the repo (deploy/.site leak)" >&2
exit 1
fi
# identity patterns live OUTSIDE the repo (untracked local file), so the
# published bytes never contain them; refuse to publish blind
if [ ! -s "$IDPAT_FILE" ]; then
echo "ABORT: identity patterns file missing/empty: $IDPAT_FILE" >&2
echo " one extended-regex per line ('#' comments); the leak scan needs it" >&2
exit 1
fi
IDPAT=$(grep -v '^[[:space:]]*#' "$IDPAT_FILE" | grep -v '^[[:space:]]*$' | paste -sd'|' -)
LEAK=$(cd "$OUT/$APP.git" && find objects -type f | while read -r f; do
# filename via argv, never interpolated into source (injection-proof pattern)
python3 -c "import zlib,sys;sys.stdout.buffer.write(zlib.decompress(open(sys.argv[1],'rb').read()))" "$f" 2>/dev/null
done | grep -aicE "$IDPAT" || true)
if [ "${LEAK:-0}" != "0" ]; then
echo "ABORT: identity strings found inside $LEAK mirror object(s)" >&2
exit 1
fi
echo "anonymity gate: OK (single anonymous author, no identity bytes, no nested site)"
# -----------------------------------------------------------------------------
echo "mirror built at $OUT ($(du -sh "$OUT" | cut -f1)) — publish via the ecosystem's assemble.sh $APP"