#!/bin/bash

# omarchy:summary=Apply Omarchy hardware-specific packages and system configuration
# omarchy:group=apply
# omarchy:requires-sudo=true
# omarchy:examples=omarchy apply hardware --install-user dhh
# omarchy:hidden=true

set -euo pipefail

usage() {
  cat <<USAGE
Usage: omarchy apply hardware --install-user USER
       omarchy apply hardware --defer-provisioning

Runs idempotent hardware detection/setup for the installed machine. This is
called by omarchy-apply-system during ISO finalization and can be rerun later
for diagnostics or after hardware/package updates.

--defer-provisioning runs without an install user (deferred-provisioning installs create the user at
first boot); group grants are recorded in /var/lib/omarchy/provisioning/groups.
USAGE
}

install_user="${OMARCHY_INSTALL_USER:-}"
defer_provisioning=0
while (($#)); do
  case "$1" in
    --install-user)
      install_user="${2:-}"
      shift 2
      ;;
    --defer-provisioning)
      defer_provisioning=1
      shift
      ;;
    -h|--help)
      usage
      exit 0
      ;;
    *)
      echo "Unknown option: $1" >&2
      usage >&2
      exit 1
      ;;
  esac
done

if (( EUID != 0 )); then
  echo "Error: omarchy-apply-hardware must run as root" >&2
  exit 1
fi

if (( defer_provisioning )); then
  install_user=""
else
  if [[ -z $install_user || $install_user == "root" ]]; then
    echo "Error: --install-user must name the target non-root user" >&2
    exit 1
  fi

  if ! getent passwd "$install_user" >/dev/null; then
    echo "Error: user '$install_user' does not exist" >&2
    exit 1
  fi
fi

export OMARCHY_INSTALL_USER="$install_user"
export OMARCHY_PATH="${OMARCHY_PATH:-/usr/share/omarchy}"
export OMARCHY_INSTALL="${OMARCHY_INSTALL:-$OMARCHY_PATH/install}"
export OMARCHY_INSTALL_LOG_FILE="${OMARCHY_INSTALL_LOG_FILE:-/var/log/omarchy-install.log}"
export PATH="$OMARCHY_PATH/bin:$PATH"

source "$OMARCHY_INSTALL/helpers/logging.sh"
source "$OMARCHY_INSTALL/hardware/all.sh"
