#!/bin/sh
#
# ArcaVir 2010 Server update script.
# Copyright (C) 2009 ArcaBit sp. z o.o.
#
# Changelog:
#
# * 20090623 gophi
#   * Created
#
# * 20090716 gophi
#   * Added GnuPG support

. /usr/share/arcavir/functions || { echo 'Cannot load /usr/share/arcavir/functions!'; exit 1; }
[ -f /etc/arcavir/arcaupdate.conf ] && . /etc/arcavir/arcaupdate.conf

[ $# -lt 1 ] && die 'Syntax: arcaupdate-get <cache path>'

cache="$@"

rawos=$(${uname} -o)
rawmach=$(${uname} -m)

os=
mach=

[ "${rawos}" = 'GNU/Linux' ] && os='linux'
# xxx more to follow

[ "${rawmach}" = 'i386' ] && mach='i386'
[ "${rawmach}" = 'i486' ] && mach='i386'
[ "${rawmach}" = 'i586' ] && mach='i386'
[ "${rawmach}" = 'i686' ] && mach='i386'
[ "${rawmach}" = 'x86_64' ] && mach='amd64'

[ "${os}" = '' ] && die "Unknown system ${rawos}"
[ "${mach}" = '' ] && die "Unknown machine ${rawmach}"

suffix=core/${os}-${mach}

verifybasessig()
{
	isprog "${gpg}"
	if [ $? -eq 0 ]; then
		${gpg} --no-default-keyring --keyring /var/lib/arcavir/pubring.gpg -q --batch --verify "${cache}/bases/arcalinuxbases.md5" >/dev/null 2>&1
		if [ $? -gt 0 ]; then
			${rm} -rf "${cache}/*"
			die 'GnuPG verify failed! Someone may be tampering with your repository.'
		fi
	fi
}

verifybase()
{
	sum=$1
	file=$2

	sum2=$(${md5sum} "${file}" | ${sed} 's/ .*$//')
	[ "$sum" = "$sum2" ] || die "File ${file} verify failed!"
}

${mkdir} -p ${cache}/bases || die 'mkdir failed'
${rsync} --no-motd -a rsync://${rsyncpath}/${suffix}/ "${cache}" 2> /dev/null
if [ $? -gt 0 ]; then
	echo 'arcaupdate-get: warning: rsync failed for core, falling back to http'
	${rm} -rf "${cache}/*" || die 'rm failed'
	cd "${cache}" || die 'cd failed'
	${wget} --quiet -N -P "${cache}" -np -nd -r -R 'index.html*' http://${httppath}/${suffix}/ || die 'wget failed'
	${rm} -f "${cache}/robots.txt"
fi

isprog "${gpg}"
if [ $? -eq 0 ]; then
	${gpg} --no-default-keyring --keyring /var/lib/arcavir/pubring.gpg -q --batch -d < "${cache}/files.gpg" > "${cache}/files.txt" 2>/dev/null
	if [ $? -gt 0 ]; then
		${rm} -rf "${cache}/*"
		die 'GnuPG verify failed! Someone may be tampering with your repository.'
	fi
else
	log_warn 'arcaupdate-get: warning: GnuPG not found. We STRONGLY suggest that you '
	log_warn 'arcaupdate-get: warning: install it. Please see the apropriate section '
	log_warn 'arcaupdate-get: warning: in README for details.'
fi

# to samo dla baz

tmpfile=/tmp/arcaupdate.tmp

${rsync} --no-motd -a rsync://${rsyncpath}/bases/ "${cache}"/bases 2> /dev/null
if [ $? -gt 0 ]; then
	echo 'arcaupdate-get: warning: rsync failed for bases, falling back to http'

	${wget} --quiet -N -P "${cache}"/bases http://${httppath}/bases/arcalinuxbases.md5 || die 'wget failed'
	verifybasessig

	/usr/bin/arcacompat dos2unix "${cache}"/bases/arcalinuxbases.md5 $tmpfile
	${grep} '  ' $tmpfile | while [ . ]; do
		read sum file || break;
		${wget} --quiet -N -O "${cache}"/bases/"${file}" http://${httppath}/bases/${file} || die 'wget failed'
		verifybase $sum "${cache}"/bases/"${file}"
	done
else
	verifybasessig

	/usr/bin/arcacompat dos2unix "${cache}"/bases/arcalinuxbases.md5 $tmpfile
	${grep} '  ' $tmpfile | while [ . ]; do
		read sum file || break;
		verifybase $sum "${cache}"/bases/"${file}"
	done
fi

${rm} -f $tmpfile

exit 0
