#!/usr/bin/env bash
# repro/signoff-certificate-engine/repro.sh -- reproduce signoff certificate v2 of `signoff-certificate-engine` by running the lab's own witness
# (scripts/audit/verify_certificate_v2_gate.py) and parsing the yield interval and the S-bound it prints.
#   exit 0   the witness passed and every parsed value matches EXPECTED.md
#   exit 1   the witness failed, or printed values that differ from EXPECTED.md
#   exit 69  ENV: a named tool is missing, so nothing was reproduced
# The witness rewrites benchmarks/certificate_v2/certificate_v2_gate_2026_07.json (its output); run it in a clone.
set -u -o pipefail
HERE="$(cd "$(dirname "$0")" && pwd)"
ROOT="$(cd "$HERE/../.." && pwd)"
cd "$ROOT" || exit 3

if ! python3 -c "import scipy.stats, numpy" >/dev/null 2>&1; then
  echo "ENV: the interpreter cannot import scipy.stats with numpy; the witness would SKIP, nothing reproduced"
  exit 69
fi

OUT="$(mktemp "${TMPDIR:-/tmp}/repro_certificate_v2.XXXXXX")"
trap 'rm -f "$OUT"' EXIT
PYTHONPATH=. python3 scripts/audit/verify_certificate_v2_gate.py >"$OUT" 2>&1
rc=$?
cat "$OUT"
if [ "$rc" -ne 0 ]; then
  echo "NOT REPRODUCED: the witness exited $rc"
  exit 1
fi
python3 repro/expect.py "$HERE/EXPECTED.md" "$OUT"
