#!/bin/busybox sh
# shellcheck shell=dash
# Stage-1 rc: sourced by /init (still PID 1, initramfs root) when a virtio
# disk is present. Emulates U-Boot's slot choice: mount the validated slot's
# rootfs and switch_root into it. This is an EMULATION of the A/B selection
# outcome, not the BCB/bootcount mechanism itself.
#
# Every guarded failure path `return`s to /init (valid in a sourced script;
# /init then falls through to shell/poweroff). The final exec is the one
# unguardable step: if switch_root itself fails to launch, the shell (PID 1)
# exits and the kernel panics; the applet-existence check below catches the
# only preventable variant of that.

# shellcheck source=qemu/rootfs/etc/warden-lib.sh disable=SC1091
. /etc/warden-lib.sh

warden_populate_by_name
slot="$(warden_slot)"

root="/dev/block/by-name/rootfs${slot}"
if [ ! -e "$root" ]; then
    echo "rc: $root missing: staying in initramfs"
    return 0
fi

mkdir -p /mnt
if ! mount -t ext4 "$root" /mnt; then
    echo "rc: mount of $root failed: staying in initramfs"
    return 0
fi
if [ ! -x /mnt/sbin/init ]; then
    echo "rc: $root has no /sbin/init: staying in initramfs"
    umount /mnt
    return 0
fi
if ! command -v switch_root >/dev/null; then
    echo "rc: busybox lacks switch_root: staying in initramfs"
    umount /mnt
    return 0
fi

# Hand the live devtmpfs to the new root: busybox switch_root moves nothing,
# and a REAL device rootfs's init expects /dev to already be there (its getty
# opens /dev/console immediately). Our own skeleton init remounts devtmpfs
# defensively either way.
mkdir -p /mnt/dev
mount -o move /dev /mnt/dev 2>/dev/null || mount --move /dev /mnt/dev

echo "rc: switching root to rootfs${slot} ($root)"
exec switch_root /mnt /sbin/init
