#!/usr/bin/env bash
set -euo pipefail
#MISE description="Cut a release: bump the patch version in Cargo.toml, then build & push silenloc/fig:<v>"
# Always run, even if nothing changed: no `sources`/`outputs` markers, which
# would otherwise let mise cache-skip the task when Cargo.toml is older than
# the last produced icon index. Releasing must always bump + build + push.
# Cut a release:
# 1. Bump the patch component of [package].version in-place.
# 2. `docker buildx build --push` builds the image from the Dockerfile using
# the newly bumped version and streams it straight to the registry
# (expects `docker login` to be configured already). Building and pushing
# in one pass skips the local image-store round trip a separate
# `docker build` + `docker push` pays for.
# 3. Commit the bumped Cargo.toml and push to the default branch.
#
# `--provenance=false` keeps the result a plain single-arch manifest: SLSA
# attestations turn it into a manifest list and add extra blobs to export and
# upload for no benefit here.
#
# Note: releases use `docker build` rather than `mise oci build` because the
# experimental OCI builder cannot RUN commands — it can neither apt-install
# the runtime `git` dependency nor create the non-root user, both of which
# broke the 0.1.86–0.1.88 images on the VPS.
# 1. Read the current version from Cargo.toml's [package].version line
# (awk scoped to [package] so dependency `version = "..."` lines are ignored).
v=$(awk '/^\[package\]/ { p=1; next }
p && /^version = / { sub(/^version = /, ""); gsub(/"/, ""); print; exit }' Cargo.toml)
# 2. Compute the next patch version.
major=$(echo "$v" | cut -d. -f1)
minor=$(echo "$v" | cut -d. -f2)
patch=$(echo "$v" | cut -d. -f3)
patch=$((patch + 1))
nv="$major.$minor.$patch"
# 3. Rewrite the first `version = "..."` line under [package] in-place.
awk -v new="$nv" '
/^\[package\]/ { p=1; print; next }
p && /^version = / { $0 = "version = \"" new "\""; p=0 }
{ print }
' Cargo.toml > Cargo.toml.tmp && mv Cargo.toml.tmp Cargo.toml
# 4. Build the release image and push it as silenloc/me:<nv> in one pass,
# also tagging the same image as silenloc/me:latest.
docker buildx build --provenance=false --push -t "silenloc/me:$nv" -t "silenloc/me:latest" .
# 5. Commit the bumped Cargo.toml and push to the default branch.
git add .
git commit -m "chore: release $nv"
git push
echo "bumped Cargo.toml to $nv; released silenloc/me:$nv"