#!/bin/sh
# script/verify-lint-image-pin: fail unless the golangci-lint image
# referenced by Dockerfile.lint and the one referenced by the main
# Dockerfile's lint stage are the same image at the same digest. Our own
# extension to scripts-to-rule-them-all, not one of its entrypoints; run
# as a gate in both files. Nothing else keeps the two pins in sync, and
# a bump applied to one alone would lint the same tree against different
# rulesets, both green.
#
# Do not hardcode the expected digest here: that is a third copy to keep
# in sync.
#
# A reference that cannot be read is a hard failure, not a skip: two
# empty strings compare equal.
set -eu

ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"

LINT_DOCKERFILE="Dockerfile.lint"
MAIN_DOCKERFILE="Dockerfile"

# Echo the single golangci-lint image reference in the named Dockerfile.
# Scans every argument of every FROM instruction rather than assuming a
# field position, so `FROM --platform=... img AS stage` reads correctly.
# Exits non-zero, with a diagnosis, unless there is exactly one.
lint_image_ref() {
    file="$1"

    if [ ! -f "$file" ]; then
        echo "verify-lint-image-pin: $file: not found" >&2
        return 1
    fi

    refs="$(
        awk '
            toupper($1) == "FROM" {
                for (i = 2; i <= NF; i++) {
                    if ($i ~ /^golangci\/golangci-lint[:@]/) {
                        print $i
                    }
                }
            }
        ' "$file"
    )"

    count="$(printf '%s' "$refs" | grep -c . || true)"
    if [ "$count" -ne 1 ]; then
        echo "verify-lint-image-pin: $file: expected exactly one" \
            "golangci/golangci-lint FROM reference, found $count" >&2
        return 1
    fi

    printf '%s\n' "$refs"
}

main() {
    cd "$ROOT"

    lint_ref="$(lint_image_ref "$LINT_DOCKERFILE")"
    main_ref="$(lint_image_ref "$MAIN_DOCKERFILE")"

    if [ "$lint_ref" != "$main_ref" ]; then
        echo "verify-lint-image-pin: the linter image is pinned twice and" \
            "the two pins disagree:" >&2
        echo "verify-lint-image-pin:   $LINT_DOCKERFILE: $lint_ref" >&2
        echo "verify-lint-image-pin:   $MAIN_DOCKERFILE: $main_ref" >&2
        echo "verify-lint-image-pin: bump both FROM lines together so" \
            "script/lint and the Dockerfile lint stage keep running the" \
            "same linter" >&2
        exit 1
    fi

    echo "verify-lint-image-pin: $LINT_DOCKERFILE and $MAIN_DOCKERFILE" \
        "agree on $lint_ref"
}

main "$@"
