#!/bin/sh
#
# Copyright 2009 The Chromium Authors
# Use of this source code is governed by a BSD-style license that can be
# found in the LICENSE file.
#
# This script is part of the yandex-browser package.
#
# It creates the repository configuration file for package updates, and it
# monitors that config to see if it has been disabled by the overly aggressive
# distro upgrade process (e.g.  intrepid -> jaunty). When this situation is
# detected, the respository will be re-enabled. If the respository is disabled
# for any other reason, this won't re-enable it.
#
# This functionality can be controlled by creating the $DEFAULTS_FILE and
# setting "repo_reenable_on_distupgrade" to "true" or "false" as desired.
# An empty $DEFAULTS_FILE is the same as setting it to "false".
#
# The $DEFAULTS_FILE also has a setting "repo_add_once" which can be set
# to "false" to prevent the package install from adding the repo altogether.

# System-wide package configuration.
DEFAULTS_FILE="/etc/default/yandex-browser"


# sources.list setting for yandex-browser updates.
REPOCONFIG="deb [arch=amd64] https://repo.yandex.ru/yandex-browser/deb stable main"
REPOCONFIGREGEX="deb (\[arch=[^]]*\bamd64\b[^]]*\][[:space:]]*) https?://repo.yandex.ru/yandex-browser/deb stable main"

# This file is automatically generated by update_key_include.py
# Do not edit this file directly.

# This is used as a priority value for the key file, so newer
# keyrings should always take priority.
PGP_KEY_VERSION=2


# pub   rsa4096 2023-05-16 [SC]
#       224974DB7FED6DECB7D855EF60B9CD3A083A7A9A
# uid                      Yandex Browser Repository Key <browser@support.yandex.ru>
# sub   rsa4096 2023-05-16 [E]

PGP_KEY_DATA=$(cat <<KEYDATA
mQINBGRjrD4BEADQ/RQI4bgIf5XpqaqZPA1EtSXpqoJphfbQ9wnMD1E4AExTf6aU
bPiKdU0g1YnCBbhl74tM2S+apQIBj+TdewF04q8nck9IBp2OSQWYXWDj7oe5DUvK
s9SgQgDQxH/+S56+m0tkJt5hjPausibfWVon7j/RQnTYG3479Qp/lCsw1OwFzpfJ
kDY16U4hLYHmYYMQ28DGiIEjYXCthhJkMo4G5I89hJQR1jgUjmkH34tV2q0y3Q06
Ln49s6O40TM18ViTK9ZiFZBsV70QsNKiTNXMSXFAINfD7+zwcmHUXpVWgBpeeYF6
ensruZbgQ3LOHqSv+Lk0w80d+3kNV+WUHDP8jz4rOx/6FIyks4Ldmk3E0/clf7B2
SkSc1xSUVV2RcqQOAOKl2ql8T167EcpbX8i9JpwRW6LSP9iUetudYTk72NKNhQbp
Iaz/LwqXquTPYYi0fsYwCTDacZ4QiHvMqLeal+4vjQIEsu+D51Y2t1gyRQ+kmCgL
zYB/1oTHvjV3Tl1ONXAJgVe4oY3wae21N+uUV00Vb1mUpHsVOjW42QivsYyLtKU0
ulDVSeOt8KwBm7cYOiZeiGn1oFz/fSNfCf+DI0PQPmKLvirCP96sRK6ERG61R2vC
iPdLAe5EVSNUKknYAUna7bjl+Hg206q4jqVrd4s0CpNt7uI79Mpcq26izQARAQAB
tDlZYW5kZXggQnJvd3NlciBSZXBvc2l0b3J5IEtleSA8YnJvd3NlckBzdXBwb3J0
LnlhbmRleC5ydT6JAk4EEwEKADgWIQQiSXTbf+1t7LfYVe9guc06CDp6mgUCZGOs
PgIbAwULCQgHAwUVCgkICwUWAgMBAAIeBQIXgAAKCRBguc06CDp6mshjD/9PnDuo
NjaGaNoP05BsGTJ5NXWX1I8yIyRH2oe99gaQa2yB9OePL0eAR3QdQos7+YT/zWQW
nHqG5aDHrhs+zRuMsG5/1eS00wMxlwzRYo73jSmCrzvRyiYFVQLiVIR8ChBEQdsG
nDPJ3+LTCFaVMJ5vlBOoHT4x/j/TehCukOAPCobqnfCHZVD/RaCIxBYFkUFsnj8h
eeUb1DSvy0G5zXYDl+fl3zfkv8qf9D6Mls0SMeqofs61rJkg0lgPd6WHcbC/MHEE
XqG/7PWgLDrMZrI4dVw7quifWsnSOTJIxhrSixP4xro5blMFxeaJx5kVb7xWsbqU
ccsOAYzJeqO4Yew0QuFeMWwKAUW9Hx3g9bs2Iu/J1OhzGpz4aDCdtXV+k3B6Al5s
Xn1Xoyqd70OP4RweSeSlufkMhsgsKQg1l+0npN3cqWV9FcxYLzdw1cPsjXIXj+8u
GXku8ax+J4VmVSGXh4lMnqQH9/WZkiKSDKkHvFfRXTIpmaUMUkH3Tw6muHkntol6
cZ+9H3/naLf+4HtYnav1jHXrYiaBQFHPFV0AsFqCIaiKS6OWME8F7plecgD56wVt
i5piS0Iz2xTDA9O50aBEwe/Zl4YQ+xuNAsuYtb2UudziPQfgS38ec2qywOZJfz+n
vSpN/t7SBZiuUr9FrWnClnhqKTAdXUPnwIx+MLkCDQRkY6w+ARAApGIX1HdNDqqd
1KyZhXTQdqkBfIFb9JFCGNVUbh9IYucPA8CSDtCmKrFrqqslNVCqEwgLu5monEzP
KNUlEf8/PsW7UQsDdAzYfN3ev7DP5xKmFf1pcxaCidj/xOTxMZegvs4v1o8JmcOa
u3leEbZWd0F0g25+AeJR7fXOFctLJthNeC19gZAG62vg7+UL+haR3ufUayqK4fh3
RYn0cjXMQseWK/YxHFbUZ+MbWwGM0454h7l1mr2pCzUH/dscuG5VjogPIUS9yVV3
467IPF1xfTv0mCJseQIt61xuUMG/+x5iWeMjd4CThEnoYMHQyEYi0BIwFlFd56iW
87NgRwngvTNRmoEQ/MGVdBOAf354p9RocUmUu3tqqzlZYwlFbRuIjSZqy/KbIEmC
HmvrKwNDukMfdd7crvWL8oc6KaoC564FNYr2rlIEpgZDO0bZ9mlRNwZM4AoSh0kw
ZE2fSDY1eEDDHZmnOULO5xuAvn7DxeUaOQ2NegeRDTkodQUotSkcEz8JiA0PbAhC
uOQYYfFbMnjbF3ckTu0w2SdrRlxnebpF7aUV+pOnrEz3L88b6OZ6BZORpMCOav4O
suu+qsoSf8f5W9wQ5VVWycQTreDJzDBbGNoYVMHbgn8A5GEeM5v0fa7Vmd03PFEX
RxGFNJ3FtZmN5X9mL89cPd8uUFY85vEAEQEAAYkCNgQYAQoAIBYhBCJJdNt/7W3s
t9hV72C5zToIOnqaBQJkY6w+AhsMAAoJEGC5zToIOnqaskcQAKtfnpkzo/jcH2tp
BCsd49V1ocQvQj+l19h3/bYG4LGxr6cZPJSPua+rktZkgjbRyuJ5j/O3IO76pD9y
BfZyzPn8+rzvO0lvJLq/5Wf8LDikWlTYX31yaF379WU+rwv7yJVw3dlUnpIO3ktE
SyEc92i9MuAs/zc8J+6ceYQlozXD2wkCwMwy+YlgdYXjX4N/lO01SJ52O9Er5L99
fyxdFDcYOvN8VxrJw2VGT6zzVyL2OUNmNsBl5Gr2P7J4G5YWAOYm+o0Ui/aEcXWs
HgTtxIyAhNT4nP8mgdB6CFJF0E7OLPk8gcubZFgXwxaoAyPPgLKVCo3+9eBbMTUu
JxxnHUWbJovHuZwFRq8eJAoTZp78ZjAvku65uSUcYayux2del94/+pksQFRwy1RF
XYdWfSMk7QNwGTWPee4Qu5bCw5Rtg/R8w6dFhVaXfbrfCkTIsu1L8QMU6Gj9Zlpx
4CGZ2xmYc6+2coXfR7NUKIWIfk3JqhD3O1xuBzFgicgJ0WjBhjsfY/a7N1JtXOcF
kJDzgMH21llsbUdvtEoZgPdyy9iTA/U7FnPpDV/+uV4sMyMNvr6nA1N8HifoMLNM
pZifZYbNHFRptZ7MGjhVmqJZl96H3D84q5253xaI4/3THgBfKWuoJiLBm4siPsC4
9f/ZjpTnNxlKtuKyXULMET5MIxzB
KEYDATA

)

PGP_KEY_CHECKSUM="=XKpA"
PGP_FINGERPRINT="224974DB7FED6DECB7D855EF60B9CD3A083A7A9A"


PGP_SUBKEYS="32EE5355A6BC6E42 FD533C07C264648F"


APT_CONFIG="$(command -v apt-config 2>/dev/null)"

GPG_FILE="/usr/share/keyrings/yandex-browser.gpg"

# Set variables for the locations of the apt trusted keyrings.
find_apt_trusted() {
  eval $("$APT_CONFIG" shell APT_TRUSTEDDIR 'Dir::Etc::trustedparts/d')
}

# Set variables for the locations of the apt sources lists.
find_apt_sources() {
  eval $("$APT_CONFIG" shell APT_SOURCESDIR 'Dir::Etc::sourceparts/d')
  SOURCES_FILE="$APT_SOURCESDIR/yandex-browser.sources"
}

# Install the repository/package signing keys. The key cannot be part of the
# package since it's still needed if the package is removed but not purged.
install_key() {
  if [ ! -e /usr/share/keyrings ]; then
    mkdir -p /usr/share/keyrings
    chmod 755 /usr/share/keyrings
  fi

  # Use a temporary file to ensure atomic updates
  echo "$PGP_KEY_DATA" | base64 -d >"$GPG_FILE.$$.tmp"
  chmod 644 "$GPG_FILE.$$.tmp"
  mv "$GPG_FILE.$$.tmp" "$GPG_FILE"
}

uninstall_key() {
  rm -f "$GPG_FILE"
}

remove_legacy_key() {
  find_apt_trusted
  rm -f "$APT_TRUSTEDDIR/yandex-browser.gpg"
}

remove_legacy_list() {
  find_apt_sources
  LEGACY_LIST="$APT_SOURCESDIR/yandex-browser.list"
  if [ ! -f "$LEGACY_LIST" ]; then
    return
  fi

  # Check for other sources (strict check for 'ours')
  # If there are any lines starting with 'deb' (commented or not) that do NOT
  # match our strict regex, keep the file.
  if grep -E "^[[:space:]]*#?[[:space:]]*deb" "$LEGACY_LIST" |
    grep -v -E \
    "^[[:space:]]*#?[[:space:]]*$REPOCONFIGREGEX" >/dev/null;
  then
    # Other sources exist, comment out ours (strict match)
    sed -i -E "s|^[[:space:]]*($REPOCONFIGREGEX)|# \1|" "$LEGACY_LIST"
  else
    # No other sources, safe to remove
    rm -f "$LEGACY_LIST"
  fi
}

# Generate the content of the .sources file
gen_sources_content() {
  DEB_BASE_REPO_CONFIG=$(echo "$REPOCONFIG" | sed -E \
    's|^deb \[arch=[^]]*\][[:space:]]+||')
  DEB_URIS=$(echo "$DEB_BASE_REPO_CONFIG" | sed -E 's/[[:space:]].*//')
  case "$DEB_URIS" in
    */) ;;
    *) DEB_URIS="${DEB_URIS}/" ;;
  esac
  DEB_REPO_REMAINING=$(echo "$DEB_BASE_REPO_CONFIG" | sed -E \
    's/^[^[:space:]]+[[:space:]]+//')
  DEB_SUITES=$(echo "$DEB_REPO_REMAINING" | sed -E 's/[[:space:]].*//')
  DEB_COMPONENTS=$(echo "$DEB_REPO_REMAINING" | sed -E \
    's/^[^[:space:]]+[[:space:]]+//')

  cat <<EOF
### THIS FILE IS AUTOMATICALLY CONFIGURED ###
# Changes to this file will not be preserved.
# This file will not be recreated if removed.
X-Repolib-Name: Yandex Browser
Types: deb
URIs: $DEB_URIS
Suites: $DEB_SUITES
Components: $DEB_COMPONENTS
Architectures: amd64
Signed-By: $GPG_FILE
EOF
}

# Add the Google repository to the apt sources. The sources cannot be part of
# the package since it's still needed if the package is removed but not purged.
create_sources_lists() {
  find_apt_sources

  gen_sources_content >"$SOURCES_FILE.$$.tmp"
  chmod 644 "$SOURCES_FILE.$$.tmp"
  mv "$SOURCES_FILE.$$.tmp" "$SOURCES_FILE"

  if [ -r "$DEFAULTS_FILE" ]; then
    if grep -q "^[[:space:]]*repo_add_once=" "$DEFAULTS_FILE"; then
      sed -i -e \
        's/^[[:space:]]*repo_add_once=.*/repo_add_once="false"/' \
        "$DEFAULTS_FILE"
    else
      echo 'repo_add_once="false"' >>"$DEFAULTS_FILE"
    fi
  fi
}

# Remove our custom sources file.
clean_sources_lists() {
  find_apt_sources
  rm -f "$SOURCES_FILE"
}

install_deb822_sources() {
  find_apt_sources
  LEGACY_LIST="$APT_SOURCESDIR/yandex-browser.list"

  SHOULD_INSTALL_SOURCES=0
  # Detect new installs.
  if [ -r "$DEFAULTS_FILE" ]; then
    if grep -E -q \
      '^[[:space:]]*repo_add_once=[[:space:]]*["'\'']?true["'\'']?' \
      "$DEFAULTS_FILE"; then
      SHOULD_INSTALL_SOURCES=1
    fi
  else
    SHOULD_INSTALL_SOURCES=1
    echo 'repo_add_once="true"' >"$DEFAULTS_FILE"
    echo 'repo_reenable_on_distupgrade="true"' >>"$DEFAULTS_FILE"
  fi

  if [ -f "$SOURCES_FILE" ]; then
    # The new .sources file already exists. Recreate it in case it got disabled
    # during a dist upgrade.
    SHOULD_INSTALL_SOURCES=1
  elif [ -f "$LEGACY_LIST" ]; then
    # Migrate a legacy .list file to the new .sources format.
    if grep -E -q "^[[:space:]]*$REPOCONFIGREGEX" "$LEGACY_LIST"; then
      SHOULD_INSTALL_SOURCES=1
    elif grep -E -q \
      "^[[:space:]]*#[[:space:]]*$REPOCONFIGREGEX[[:space:]]*# disabled on \
upgrade to .*" \
      "$LEGACY_LIST"; then
      SHOULD_INSTALL_SOURCES=1
    fi
  fi

  if [ "$SHOULD_INSTALL_SOURCES" -eq 1 ]; then
    create_sources_lists
  fi
}

DEFAULT_ARCH="amd64"

get_lib_dir() {
  if [ "$DEFAULT_ARCH" = "i386" ]; then
    LIBDIR=lib/i386-linux-gnu
  elif [ "$DEFAULT_ARCH" = "amd64" ]; then
    LIBDIR=lib/x86_64-linux-gnu
  elif [ "$DEFAULT_ARCH" = "armhf" ]; then
    LIBDIR=lib/arm-linux-gnueabihf
  elif [ "$DEFAULT_ARCH" = "arm64" ]; then
    LIBDIR=lib/aarch64-linux-gnu
  elif [ "$DEFAULT_ARCH" = "mipsel" ]; then
    LIBDIR=lib/mipsel-linux-gnu
  elif [ "$DEFAULT_ARCH" = "mips64el" ]; then
    LIBDIR=lib/mips64el-linux-gnuabi64
  else
    echo Unknown CPU Architecture: "$DEFAULT_ARCH"
    exit 1
  fi
}


## MAIN ##
if [ -r "$DEFAULTS_FILE" ]; then
  . "$DEFAULTS_FILE"
fi

# Always try to install repo key
install_key

if [ "$repo_add_once" = "true" ]; then
  create_sources_lists
elif [ "$repo_reenable_on_distupgrade" = "true" ]; then
  install_deb822_sources
fi
