#!/bin/sh
# userland/fasadas/launchers/ffrun -> /bin/ffrun
#
# The SHELL entry point for the same Firefox the dock starts, and nothing more.
#
# ---------------------------------------------------------------------------
# WHY THIS FILE STOPPED CARRYING A PREF LIST (2026-09-06)
# ---------------------------------------------------------------------------
# It used to hold its own copy of the port's prefs and seed them itself, with
# the same guard the bundle's launcher had:
#
#     if [ ! -f "$PROFILE/user.js" ]; then cat > "$PROFILE/user.js" <<'EOF'
#
# Two defects came out of that, and the second is the worse one.
#
# 1. A profile written by an older launcher never gained a pref added later, so
#    a pref fix shipped in a new package reached nobody who had already started
#    the browser once. On the Dell the root is persistent ext4 since the HDD
#    install and $HOME/.mozilla/ffprofile survives every reboot and every
#    `apkg upgrade`. Measured 2026-09-06: a profile written by the older
#    launcher was still missing security.sandbox.content.level (#580, every
#    remote page renders WHITE), dom.ipc.processHangMonitor (#601, content
#    SIGKILLed mid-decode) and media.audioipc.shm_area_size (#605, AudioIPC
#    SIGKILL storm) after a fresh launch. Two of the three are the fixes for
#    process-kill storms, which is exactly what the owner reports dmesg full of.
#
# 2. TWO launchers seeded the SAME profile path with SEPARATE copies of the
#    list, and this one passed `--profile`, which makes the bundle's ffstart
#    skip its own seeding entirely (`want_profile=0`). So a shell launch got
#    THIS list -- which never carried the WebGL block -- a dock launch got
#    ffstart's, and after the first run neither could change the other's
#    result. The two lists happened to agree on the core prefs. Nothing made
#    them agree and nothing would have reported it when they stopped.
#
# So the pref list has exactly one owner now: ports/firefox/ffstart, the
# bundle's `Exec=`. This file execs the bundle and lets that run.
#
# THE ENVIRONMENT SURVIVES THE HOP, which is what makes that possible:
# aoprun.c:168 is `execve(binpath, av, environ)` and aoprun only ADDS
# LD_LIBRARY_PATH, AOP_BUNDLE and FONTCONFIG_FILE (the last with overwrite=0).
# So FFRUN_PROFILE and FASADAS_SOCKET set here still reach ffstart, and so does
# FF_HW_WEBRENDER from the caller's own shell.
#
# And `--profile` is deliberately NOT passed any more: passing it was the thing
# that silenced ffstart's seeding. ffstart defaults to the same
# ${FFRUN_PROFILE:-$HOME/.mozilla/ffprofile}, so the profile path is unchanged.
# A caller who really wants a different profile can still say so -- `ffrun
# --profile /path` forwards it, and ffstart then leaves that profile alone,
# which is the documented behaviour for a caller who named one.
set -u

BUNDLE="${FFRUN_BUNDLE:-/Applications/Firefox.aop}"

export FASADAS_SOCKET="${FASADAS_SOCKET:-/run/fasadas-0}"
export HOME="${HOME:-/root}"
# Everything else -- GDK_BACKEND=fasadas, MOZ_CRASHREPORTER_DISABLE,
# FONTCONFIG_FILE, LIBGL_DRIVERS_PATH, MOZ_WEBGL_FORCE_EGL -- belongs to
# ffstart, for the same reason the prefs do: one owner.

# REFUSE rather than start an unseeded browser. An installed bundle that
# predates ffstart has `Exec=firefox`, and aoprun would then run the raw binary
# with no prefs at all: every remote page white, content processes killed, and
# nothing anywhere saying the launcher was bypassed. That failure looks exactly
# like a browser bug, which is why it must not be silent.
info="$BUNDLE/Contents/Info"
if [ ! -f "$info" ]; then
    echo "ffrun: no bundle at $BUNDLE ($info is missing)." >&2
    echo "       Firefox does not appear to be installed. Try: apkg install Firefox" >&2
    exit 1
fi
exec_name=$(sed -n 's/^Exec=//p' "$info" | head -1)
if [ "$exec_name" != "ffstart" ]; then
    echo "ffrun: $BUNDLE has Exec=${exec_name:-<unset>}, not ffstart." >&2
    echo "       That bundle predates the launcher that seeds the port's prefs," >&2
    echo "       so starting it would give a browser with none of them: white" >&2
    echo "       remote pages (#580) and content processes killed (#601, #605)." >&2
    echo "       Refusing. Reinstall the package: apkg install --force Firefox" >&2
    exit 1
fi

exec aoprun "$BUNDLE" "$@"
