# Maintainer: Emiliano Gandini Outeda <emiliano.gandini@protonmail.com>
#
# Build the checkout this file sits in, with no download.
#
# The release PKGBUILD in packaging/aur/ pins one published tarball so AUR
# and release builds are reproducible.  That means it fetches the sources a
# second time, from GitHub, and fails whenever the checkout and the asset
# disagree.  This recipe is the other half: `cd packaging/local && makepkg
# -si` builds exactly the tree you cloned and reviewed, offline.
#
# source=() is intentional.  There is nothing to fetch; the "source" is the
# parent checkout, and pkgver() derives the version from its tags.

pkgname=trustsight
pkgver=0.0.0
pkgrel=1
pkgdesc='Audits AUR PKGBUILD updates before install: structure, commands, novelty'
arch=('any')
url='https://github.com/emiliano-go/trustsight'
license=('MIT')
depends=(
  'python'
  'python-pygit2'
  'python-tldextract'
  'python-rich'
  'python-typer'
  'python-cryptography'
)
makedepends=(
  'git'
  'python-build'
  'python-installer'
  'python-wheel'
  'python-hatchling'
  'python-pytest'
)
optdepends=(
  'pyalpm: native version comparison (faster discovery)'
)
source=()
sha256sums=()

pkgver() {
  cd "$startdir/../.."
  # A shallow clone of master has no tags, where `git describe` fails and a
  # bare pipe would yield an empty pkgver and abort makepkg.  Capture it
  # first so the failure is visible, and fall back to a commit-derived
  # version.
  local describe
  if describe=$(git describe --long --tags --match 'v[0-9]*' 2>/dev/null); then
    printf '%s\n' "$describe" | sed 's/^v//; s/\([^-]*-g\)/r\1/; s/-/./g'
  else
    printf '0.0.0.r%s.g%s\n' \
      "$(git rev-list --count HEAD)" "$(git rev-parse --short HEAD)"
  fi
}

build() {
  cd "$startdir/../.."
  python -m build --wheel --no-isolation
}

check() {
  cd "$startdir/../.."
  # Test the wheel this recipe just built, with the interpreter that will
  # import it.  The venv inherits the system site-packages, so the declared
  # depends and makedepends (including python-pytest) come from the system
  # and nothing is fetched from PyPI.  Installing the wheel into the venv's
  # own site-packages puts it ahead of any installed `trustsight` on
  # sys.path, so the check exercises the build, not a stale package or src/.
  local venv="$srcdir/_test-env"
  mkdir -p "$srcdir"
  rm -rf "$venv"
  python -m venv --system-site-packages "$venv"
  # Drop inherited trustsight files so the fresh wheel installs cleanly.
  find "$venv/lib" -path '*/trustsight*' -exec rm -rf {} + 2>/dev/null || true
  rm -f "$venv/bin/trustsight"
  "$venv/bin/python" -m installer dist/*.whl
  "$venv/bin/python" -m pytest tests/ -q \
    --ignore=tests/test_fetcher.py --ignore=tests/test_rebaseline.py
}

package() {
  cd "$startdir/../.."
  python -m installer --destdir="$pkgdir" dist/*.whl
  install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
  install -Dm644 README.md "$pkgdir/usr/share/doc/$pkgname/README.md"
}

# vim:set ts=2 sw=2 et:
