#!/bin/bash
set -euo pipefail

readonly script_dir="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)"
readonly minimum_version="2.46.0"
# Sentinel identifying any copy of this shim, including a sibling checkout's.
# Deliberately repo-neutral: this shim and its CoCO descendant are the same
# script, and a machine carrying both must have each recognise the other.
readonly shim_marker="hermit-git-shim-v1"

# Re-entry guard. Skipping only ${script_dir} below is not enough on its own:
# two checkouts of this repo on one PATH each strip their own bin/ and resolve
# git to the *other* shim, which resolves back — mutual recursion that forks
# until the process table is exhausted and every fork() on the machine fails.
# The marker scan below prevents that; this guard makes any residual loop a
# single loud error instead of a machine-wide outage. It is unset before the
# final exec so real git (and hooks that shell out to git) never see it.
if [[ -n "${HERMIT_GIT_SHIM_ACTIVE:-}" ]]; then
  echo "error: the Hermit git shim re-entered itself resolving 'git'." >&2
  echo "       PATH still contains another copy of this shim; no system Git was reached." >&2
  echo "       PATH=${PATH}" >&2
  exit 1
fi
export HERMIT_GIT_SHIM_ACTIVE=1

# Git is Hermit's own transport and therefore cannot safely be a Hermit package:
# doing so recursively invokes Hermit while it holds its package lock. Keep this
# tracked environment shim in bin/ so activation still enforces the protocol
# floor before any repository operation reaches credential negotiation.
path_without_hermit=""
IFS=: read -r -a path_entries <<<"${PATH}"
for entry in "${path_entries[@]}"; do
  [[ "${entry}" == "${script_dir}" ]] && continue
  # Drop sibling copies of this shim (other worktrees/checkouts on PATH), not
  # just our own directory — see the re-entry guard above for why.
  if [[ -f "${entry}/git" ]] && grep -qF "${shim_marker}" "${entry}/git" 2>/dev/null; then
    continue
  fi
  path_without_hermit="${path_without_hermit:+${path_without_hermit}:}${entry}"
done

system_git="$(PATH="${path_without_hermit}" command -v git || true)"
if [[ -z "${system_git}" ]]; then
  echo "error: Git ${minimum_version} or newer is required; no system Git was found" >&2
  exit 1
fi

installed_version="$(${system_git} --version | awk '{print $3}')"
version_at_least() {
  local installed="$1" required="$2" installed_part required_part index
  local -a installed_parts required_parts
  IFS=. read -r -a installed_parts <<<"${installed}"
  IFS=. read -r -a required_parts <<<"${required}"
  for index in 0 1 2; do
    installed_part="${installed_parts[${index}]:-0}"
    required_part="${required_parts[${index}]:-0}"
    ((10#${installed_part} > 10#${required_part})) && return 0
    ((10#${installed_part} < 10#${required_part})) && return 1
  done
  return 0
}

if ! version_at_least "${installed_version}" "${minimum_version}"; then
  echo "error: Git ${minimum_version} or newer is required for Meridian Nostr authentication (found ${installed_version})" >&2
  if [[ "$(uname -s)" == "Darwin" ]]; then
    echo "Install a current Git (for example, 'brew install git'), then reactivate Hermit." >&2
  fi
  exit 1
fi

# Real git must not inherit the guard: git hooks legitimately shell out to git,
# and a leaked guard would fail them as though they were the recursion.
unset HERMIT_GIT_SHIM_ACTIVE
exec "${system_git}" "$@"
