#!/bin/sh

PROG="${0##*/}"

sh_functions=/usr/lib/grub/grub-efi-sh-functions
if [ ! -r "$sh_functions" ]; then
    echo "$PROG: cannot load $sh_functions" >&2
    exit 1
fi
. "$sh_functions"

if [ ! -d /sys/firmware/efi ]; then
    echo "Not booted in EFI mode, unable to update EFI GRUB"
    exit 0
fi

if [ ! -f "$GRUB_SYSCONF" ]; then
    echo "There is no $GRUB_SYSCONF, nothing to do"
    exit 0
fi

. "$GRUB_SYSCONF"

if [ "${GRUB_DISABLE_AUTOUPDATE:-}" = true ] || \
         [ "${GRUB_DISABLE_AUTOUPDATE:-}" = yes ]; then
    exit 0
fi

bootloader_id="${GRUB_BOOTLOADER_ID:-$DEFAULT_BOOTLOADER_ID}"

# Auto-discover ESP mount point
EFI_DIR="$(esp_find)" || EFI_DIR=
if [ -z "$EFI_DIR" ]; then
    echo "No ESP found at /boot/efi, /efi, or /boot" >&2
    exit 1
fi
echo "Found ESP at $EFI_DIR"

# Determine EFI architecture suffix
arch_info="$(efi_arch_info "$(uname -m)")" \
    || { echo "Unsupported EFI architecture: $(uname -m)" >&2; exit 1; }
read efi_suffix efi_suffix_upper grub_target <<EOF
$arch_info
EOF

# Use .sbat section to determine ALT efi binary
is_alt_efi_binary() {
    local expected_package_name="$1"
    local efi_binary="$2"

    [ -r "$efi_binary" ] || return 1

    local sbat_component sbat_gen
    local vendor_name vendor_package_name vendor_version vendor_url
    local last_sbat_entry

    last_sbat_entry="$(grub-dumpsbat "$efi_binary" 2>/dev/null |\
                          tr -d '\0' | tail -n1)"

    IFS=, read -r sbat_component sbat_gen vendor_name vendor_package_name \
          vendor_version vendor_url <<EOF
$last_sbat_entry
EOF

    if [ "$vendor_name" = "ALT Linux" ] && \
           [ "$vendor_package_name" = "$expected_package_name" ]; then
        return 0
    else
        return 1
    fi
}

# Probe all candidate EFI binaries
echo "Probing ALT Linux EFI binaries on ESP"

dist_shim=0; dist_grub=0
boot_is_grub=0; boot_is_shim=0; boot_grub=0

dist_shim_path="$(esp_resolve_path "$EFI_DIR" "EFI/$bootloader_id/shim${efi_suffix}.efi")"
dist_grub_path="$(esp_resolve_path "$EFI_DIR" "EFI/$bootloader_id/grub${efi_suffix}.efi")"
boot_efi_path="$(esp_resolve_path "$EFI_DIR" "EFI/BOOT/BOOT${efi_suffix_upper}.EFI")"
boot_grub_path="$(esp_resolve_path "$EFI_DIR" "EFI/BOOT/grub${efi_suffix}.efi")"

if is_alt_efi_binary shim "$dist_shim_path"; then
    dist_shim=1
    echo "  $dist_shim_path: ALT shim"
fi
if is_alt_efi_binary grub "$dist_grub_path"; then
    dist_grub=1
    echo "  $dist_grub_path: ALT grub"
fi
if is_alt_efi_binary grub "$boot_efi_path"; then
    boot_is_grub=1
    echo "  $boot_efi_path: ALT grub"
fi
if is_alt_efi_binary shim "$boot_efi_path"; then
    boot_is_shim=1
    echo "  $boot_efi_path: ALT shim"
fi
if is_alt_efi_binary grub "$boot_grub_path"; then
    boot_grub=1
    echo "  $boot_grub_path: ALT grub"
fi

INSTALL_ARGS=

# Determine installation mode (most specific first)
if [ "$dist_shim" = 1 ] && [ "$dist_grub" = 1 ]; then
    echo "Detected: Secure Boot (non-removable)"
    INSTALL_ARGS=""
elif [ "$boot_is_shim" = 1 ] && [ "$boot_grub" = 1 ]; then
    echo "Detected: Secure Boot (removable)"
    INSTALL_ARGS="--removable"
elif [ "$boot_is_grub" = 1 ] && [ "$dist_grub" = 1 ]; then
    echo "Detected: no Secure Boot (force-extra-removable)"
    INSTALL_ARGS="--force-extra-removable"
elif [ "$dist_grub" = 1 ]; then
    echo "Detected: no Secure Boot (non-removable)"
    INSTALL_ARGS=""
elif [ "$boot_is_grub" = 1 ]; then
    echo "Detected: no Secure Boot (removable)"
    INSTALL_ARGS="--removable"
else
    echo
    echo "ALT Linux EFI GRUB image was not found, nothing to update."
    echo "To install GRUB bootloader, please run: grub-efi-install"
    echo
    echo "If your system lacks NVRAM or you are getting persistent"
    echo "errors, please run:"
    echo "grub-efi-install --removable"
    echo
    exit 0
fi

echo "Updating grub in $EFI_DIR${INSTALL_ARGS:+ with $INSTALL_ARGS}"
grub-efi-install --efi-directory="$EFI_DIR" $INSTALL_ARGS
