#!/usr/bin/env bash
set -e

mkdir -p /var/run/sshd

KALI_ROOT_PASSWORD="$(sed -n '/^KALI_ROOT_PASSWORD=/{s/^[^=]*=//; s/^"//; s/"$//; p;}' /run/pentest-copilot.env | tail -1)"
if [ -z "$KALI_ROOT_PASSWORD" ]; then
    echo "ERROR: KALI_ROOT_PASSWORD is not configured" >&2
    exit 1
fi
echo "root:${KALI_ROOT_PASSWORD}" | chpasswd
unset KALI_ROOT_PASSWORD

# Start SSH — use the daemon directly so we get a clean PID and proper error reporting
/usr/sbin/sshd -D &
SSHD_PID=$!

# Wait briefly and verify sshd is alive
sleep 1
if ! kill -0 "$SSHD_PID" 2>/dev/null; then
    echo "ERROR: sshd failed to start" >&2
    exit 1
fi
echo "sshd running (pid $SSHD_PID)"

# Launch shellinabox on port 4200 (no SSL) for browser-based shell access
shellinaboxd --disable-ssl --port 4200 -s "/:LOGIN" &

# If an OpenVPN configuration exists, start the OpenVPN service
if [ -f /etc/openvpn/server.conf ]; then
    echo "Starting OpenVPN server..."
    openvpn --config /etc/openvpn/server.conf &
fi

# Keep the container running
wait "$SSHD_PID"
