# VERSION is overridable (the Dockerfile passes its ARG VERSION in) and
# degrades to "dev" when git is unavailable or there is no .git — the
# build must not depend on the repository history being in the build
# context.
VERSION ?= $(shell { git describe --always --dirty; } 2>/dev/null || echo dev)
BUILDARCH := $(shell uname -m)
BINARY := netwatch-server

GOLDFLAGS += -s -w
GOLDFLAGS += -X main.Version=$(VERSION)
GOLDFLAGS += -X main.Buildarch=$(BUILDARCH)

# macOS ships shasum rather than sha256sum.
SHA256SUM := $(shell command -v sha256sum >/dev/null 2>&1 && echo sha256sum || echo shasum -a 256)

# .golangci.yml is standardized org-wide and must never be edited here
# (REPO_POLICIES.md). Its last silent drift replaced the v2 schema with
# v1 keys, which left every threshold in the file inert while the build
# stayed green. The lint target therefore asserts the file still matches
# the canonical copy byte for byte. The check is a local hash comparison:
# no network, no remote schema, nothing unpinned in the build path.
GOLANGCI_CONFIG_SHA256 := 021cc83f4e6fc7c31b95b34b846723dfcf20b66b7baeea1dc40406e643346bcb

.PHONY: all build test lint fmt fmt-check check docker hooks run clean

all: build

build:
	CGO_ENABLED=0 go build -trimpath -ldflags "$(GOLDFLAGS)" \
		-o ./$(BINARY) ./cmd/netwatch-server/

test:
	timeout 30 go test ./...

lint:
	@actual=$$($(SHA256SUM) .golangci.yml | cut -d' ' -f1); \
	if [ "$$actual" != "$(GOLANGCI_CONFIG_SHA256)" ]; then \
		echo ".golangci.yml has drifted from the org standard."; \
		echo "  expected $(GOLANGCI_CONFIG_SHA256)"; \
		echo "  actual   $$actual"; \
		echo "Restore it verbatim from sneak/prompts; do not edit it."; \
		exit 1; \
	fi
	golangci-lint run ./...

fmt:
	go fmt ./...

fmt-check:
	@test -z "$$(gofmt -l .)" || \
		(echo "Files not formatted:"; gofmt -l .; exit 1)

check: test lint fmt-check

docker:
	timeout 300 docker build -t netwatch-server -f ../Dockerfile.backend ..

hooks:
	@printf '#!/bin/sh\ncd backend && make check\n' > \
		$$(git rev-parse --show-toplevel)/.git/hooks/pre-commit
	@chmod +x \
		$$(git rev-parse --show-toplevel)/.git/hooks/pre-commit
	@echo "Pre-commit hook installed"

run: build
	./$(BINARY)

clean:
	rm -f ./$(BINARY)
