post_install() {
    :
#!/bin/bash

if type update-alternatives 2>/dev/null >&1; then
    # Remove previous link if it doesn't use update-alternatives
    if [ -L '/usr/bin/ednovas-cloud' -a -e '/usr/bin/ednovas-cloud' -a "`readlink '/usr/bin/ednovas-cloud'`" != '/etc/alternatives/ednovas-cloud' ]; then
        rm -f '/usr/bin/ednovas-cloud'
    fi
    update-alternatives --install '/usr/bin/ednovas-cloud' 'ednovas-cloud' '/opt/EdNovasCloud/ednovas-cloud' 100 || ln -sf '/opt/EdNovasCloud/ednovas-cloud' '/usr/bin/ednovas-cloud'
else
    ln -sf '/opt/EdNovasCloud/ednovas-cloud' '/usr/bin/ednovas-cloud'
fi

# Check if user namespaces are supported by the kernel and working with a quick test:
if ! { [[ -L /proc/self/ns/user ]] && unshare --user true; }; then
    # Use SUID chrome-sandbox only on systems without user namespaces:
    chmod 4755 '/opt/EdNovasCloud/chrome-sandbox' || true
else
    chmod 0755 '/opt/EdNovasCloud/chrome-sandbox' || true
fi

if hash update-mime-database 2>/dev/null; then
    update-mime-database /usr/share/mime || true
fi

if hash update-desktop-database 2>/dev/null; then
    update-desktop-database /usr/share/applications || true
fi

# Install apparmor profile. (Ubuntu 24+)
# First check if the version of AppArmor running on the device supports our profile.
# This is in order to keep backwards compatibility with Ubuntu 22.04 which does not support abi/4.0.
# In that case, we just skip installing the profile since the app runs fine without it on 22.04.
#
# Those apparmor_parser flags are akin to performing a dry run of loading a profile.
# https://wiki.debian.org/AppArmor/HowToUse#Dumping_profiles
#
# Unfortunately, at the moment AppArmor doesn't have a good story for backwards compatibility.
# https://askubuntu.com/questions/1517272/writing-a-backwards-compatible-apparmor-profile
if apparmor_status --enabled > /dev/null 2>&1; then
  APPARMOR_PROFILE_SOURCE='/opt/EdNovasCloud/resources/apparmor-profile'
  APPARMOR_PROFILE_TARGET='/etc/apparmor.d/ednovas-cloud'
  if apparmor_parser --skip-kernel-load --debug "$APPARMOR_PROFILE_SOURCE" > /dev/null 2>&1; then
    cp -f "$APPARMOR_PROFILE_SOURCE" "$APPARMOR_PROFILE_TARGET"

    # Updating the current AppArmor profile is not possible and probably not meaningful in a chroot'ed environment.
    # Use cases are for example environments where images for clients are maintained.
    # There, AppArmor might correctly be installed, but live updating makes no sense.
    if ! { [ -x '/usr/bin/ischroot' ] && /usr/bin/ischroot; } && hash apparmor_parser 2>/dev/null; then
      # Extra flags taken from dh_apparmor:
      # > By using '-W -T' we ensure that any abstraction updates are also pulled in.
      # https://wiki.debian.org/AppArmor/Contribute/FirstTimeProfileImport
      apparmor_parser --replace --write-cache --skip-read-cache "$APPARMOR_PROFILE_TARGET"
    fi
  else
    echo "Skipping the installation of the AppArmor profile as this version of AppArmor does not seem to support the bundled profile"
  fi
fi

# ---------------------------------------------------------------------------
# EdNovas: 给内核授予网络管理能力, 供 TUN 模式使用
# 以上部分是 electron-builder 26.4.0 自带的 after-install.tpl, 原样保留 (自定义 afterInstall 会整体替换默认脚本,
# 少了它 /usr/bin 链接、chrome-sandbox 权限、AppArmor 配置都不会装)。升级 electron-builder 时对照新模板同步。
# ⚠️ 本文件会做模板替换: 美元符 + 花括号包英文名 会被当成模板变量, 未定义就构建失败。shell 变量一律写成 $var, 不要加花括号。
#
# TUN 要建虚拟网卡、改路由表。以前靠把整个软件以 root 重启, 在 Wayland 或没有 polkit 认证代理的桌面上
# 窗口都开不出来。改为只给内核文件授予网络能力, 软件本身保持普通用户运行 (能力清单的依据见 electron/main.ts 的 LINUX_TUN_CAPS)。
# deb / rpm 每次安装和升级都会执行这里; pacman 升级只执行 post_upgrade, 由 pacman-post-upgrade.sh 负责 (内容须保持一致)。
# 升级替换了内核文件, 旧的授权随文件一起失效, 所以每次都要重新授予。
# 没执行到这里的安装方式 (如第三方 AUR 包只解包文件) 由软件在首次开 TUN 时弹一次密码框补授。
if command -v setcap >/dev/null 2>&1; then
  for core in '/opt/EdNovasCloud/resources/bin/EdNovas-Core' '/opt/EdNovasCloud/resources/bin/EdNovas-Core-compatible'; do
    if [ -f "$core" ]; then
      setcap 'cap_net_admin,cap_net_raw,cap_net_bind_service=+ep' "$core" || echo "EdNovas: setcap failed for $core (TUN will ask for authorization on first use)"
    fi
  done
else
  echo "EdNovas: setcap not found (install libcap / libcap2-bin); TUN will ask for authorization on first use"
fi

}
post_upgrade() {
    :
#!/bin/bash
# EdNovas: pacman 升级时执行 (经 fpm 的 --after-upgrade 写进 .INSTALL 的 post_upgrade)。
# pacman 升级只调用 post_upgrade、不调用 post_install, 而 electron-builder 只把 afterInstall 接到 post_install:
# 不补这个, 每次 pacman 升级替换内核文件后授权就丢了 (Arch 官方的 wireshark 包同样在两处都执行 setcap)。
# ⚠️ 这个脚本经 fpm 参数原样传入, 不做 electron-builder 的模板替换: 路径只能写死, 须与 after-install.sh 渲染后的
#    /opt/EdNovasCloud 保持一致; 能力清单须与 after-install.sh 和 electron/main.ts 的 LINUX_TUN_CAPS 一致。
if command -v setcap >/dev/null 2>&1; then
  for core in /opt/EdNovasCloud/resources/bin/EdNovas-Core /opt/EdNovasCloud/resources/bin/EdNovas-Core-compatible; do
    if [ -f "$core" ]; then
      setcap 'cap_net_admin,cap_net_raw,cap_net_bind_service=+ep' "$core" || echo "EdNovas: setcap failed for $core (TUN will ask for authorization on first use)"
    fi
  done
else
  echo "EdNovas: setcap not found (sudo pacman -S libcap); TUN will ask for authorization on first use"
fi

}
post_remove() {
    :
#!/bin/bash

# Delete the link to the binary
if type update-alternatives >/dev/null 2>&1; then
    update-alternatives --remove 'ednovas-cloud' '/usr/bin/ednovas-cloud'
else
    rm -f '/usr/bin/ednovas-cloud'
fi

APPARMOR_PROFILE_DEST='/etc/apparmor.d/ednovas-cloud'

# Remove apparmor profile.
if [ -f "$APPARMOR_PROFILE_DEST" ]; then
  rm -f "$APPARMOR_PROFILE_DEST"
fi
}
