# A machine that has never seen this project: Debian, PostgreSQL from the PostgreSQL
# project's own apt repository, a stranger's toolchain, and the repository as git has it.
# Everything the verification needs is installed here, from where anyone gets it, and
# nothing comes from the machine that wrote the code. Built by tests/clean-machine/run.sh,
# which is also what CI runs (.github/workflows/verify.yml) -- one definition of
# "verified", not two that can drift.
#
# PG_MAJOR picks the version. PGDG publishes each major in its own component, betas
# included, so 19 resolves to the newest 19 beta without naming it here.
FROM docker.io/library/debian:bookworm-slim@sha256:7c7b2c966bc9ee8cedfeef67e0e279108992c77681fa595db4a9d65c06ccc587

ARG PG_MAJOR=18
ARG PGRX_VERSION=0.19.2

RUN apt-get update \
 && apt-get install -y --no-install-recommends ca-certificates curl \
 && install -d /usr/share/postgresql-common/pgdg \
 && curl -fsSo /usr/share/postgresql-common/pgdg/apt.postgresql.org.asc \
      https://www.postgresql.org/media/keys/ACCC4CF8.asc \
 && echo "deb [signed-by=/usr/share/postgresql-common/pgdg/apt.postgresql.org.asc] https://apt.postgresql.org/pub/repos/apt bookworm-pgdg main $PG_MAJOR" \
      > /etc/apt/sources.list.d/pgdg.list \
 && apt-get update \
 && apt-get install -y --no-install-recommends \
      postgresql-$PG_MAJOR postgresql-server-dev-$PG_MAJOR \
      build-essential clang libclang-dev pkg-config git make \
 && rm -rf /var/lib/apt/lists/*

# Not root: initdb refuses root, and a stranger's machine is not run as root either. The
# user owns the PostgreSQL directories pgrx's unit tests and `make install` write into.
RUN useradd -m tester \
 && chown -R tester /usr/lib/postgresql/$PG_MAJOR/lib /usr/share/postgresql/$PG_MAJOR/extension
USER tester
ENV PATH=/home/tester/.cargo/bin:/usr/lib/postgresql/$PG_MAJOR/bin:$PATH \
    PG_CONFIG=/usr/lib/postgresql/$PG_MAJOR/bin/pg_config \
    USER=tester

RUN curl -sSf https://sh.rustup.rs | sh -s -- -y --profile minimal --default-toolchain 1.98.0
RUN cargo install cargo-pgrx --version "$PGRX_VERSION" --locked
RUN cargo pgrx init --pg$PG_MAJOR "$PG_CONFIG"

# The one dependency outside this repository, from its public repository.
RUN git clone --depth 1 --branch v0.5.5 https://github.com/Manuelreyesbravo/pg_living_assertions /home/tester/pg_living_assertions \
 && make -C /home/tester/pg_living_assertions install PG_CONFIG="$PG_CONFIG"

# uv brings the one Python dependency the suites use (psycopg, for tests/flushes.sh and the
# fuzzer), pinned, from its own installer -- like cargo-pgrx and PostgreSQL above.
RUN curl -LsSf https://astral.sh/uv/0.12.23/install.sh | sh
ENV PATH=/home/tester/.local/bin:$PATH

COPY --chown=tester . /home/tester/pg_agent_gate
WORKDIR /home/tester/pg_agent_gate
CMD ["make", "verify"]
