#!/usr/bin/env bash
# blender-run — one-shot HEADLESS Blender on fv-ml1 GPU 3, for scripted/CLI callers (draupnir etc.).
# The agent-driven, interactive path is scripts/blender-mcp; this is the batch path.
#
#   scripts/blender-run [--job DIR] -- <blender args after -b>
#   scripts/blender-run --job /mnt/smithy/draupnir/j42 -- --python render.py -- --out out.png
#   scripts/blender-run -- --python-expr 'import bpy; print(bpy.app.version_string)'
#
# Each call is its own `docker run --rm` of the stacks/blender image (Blender 5.2.2 LTS, Python
# 3.13): no desktop, no MCP socket, gone when Blender exits. So it never collides with the on-demand
# GUI container, and GPU 3 goes back to 0 when the render ends. Always added: `-b --factory-startup
# --python-exit-code 1`. Without that last flag, Blender exits 0 even when a --python script raises
# (measured).
#
# ⚠ Give render.filepath an ABSOLUTE path (os.path.abspath). Blender does not resolve a relative
#   output path against the working directory: "cannot save 'out.png'". Python file I/O and
#   importers do use the cwd.
#
# Files: fv-ml1 does NOT mount /mnt/smithy. With --job DIR, DIR is copied to
# fv-ml1:/tank/blender/jobs/<name>/, Blender runs WITH THAT AS ITS WORKING DIRECTORY, and new or
# changed files are copied back into DIR afterwards (nothing is deleted on either side). Use
# relative paths inside the job. Without --job, the only paths Blender sees are under
# /work (= fv-ml1:/tank/blender).
#
# Budget: GPU 3 (96 GB, borrowed from the vLLM reserve: this ends if a full-size seat moves in).
# The container is capped at 64 GB RAM / 48 CPUs so a runaway render cannot starve the inference
# seats on the same host.
set -euo pipefail

HOST=${BLENDER_SSH_HOST:-infra-ops@10.251.50.54}
ENV_FILE=/opt/docker/compose/blender/.env
JOB=""
while [ $# -gt 0 ]; do
  case "$1" in
    --job) JOB=${2:?--job needs a directory}; shift 2 ;;
    --) shift; break ;;
    -h|--help) sed -n 2,23p "$0"; exit 0 ;;
    *) echo "blender-run: unknown option $1 (blender args go after --)" >&2; exit 2 ;;
  esac
done

WORKDIR=/work
if [ -n "$JOB" ]; then
  [ -d "$JOB" ] || { echo "blender-run: --job $JOB is not a directory" >&2; exit 2; }
  NAME=$(basename "$(realpath "$JOB")")
  [[ $NAME =~ ^[A-Za-z0-9._-]+$ ]] || { echo "blender-run: job dir name '$NAME' must be [A-Za-z0-9._-]" >&2; exit 2; }
  ssh -n -o BatchMode=yes "$HOST" "mkdir -p /tank/blender/jobs/$NAME"
  rsync -a "$JOB"/ "$HOST:/tank/blender/jobs/$NAME/"
  WORKDIR=/work/jobs/$NAME
fi

# Arguments travel as one shell-quoted string: ssh flattens argv into a remote command line.
ARGS=$(printf '%q ' "$@")
set +e
ssh -n -o BatchMode=yes "$HOST" "IMG=\$(grep '^IMAGE=' $ENV_FILE | cut -d= -f2) && \
  exec docker run --rm --name blender-run-\$\$ --runtime nvidia \
    -e NVIDIA_VISIBLE_DEVICES=3 -e NVIDIA_DRIVER_CAPABILITIES=all \
    --user 1002:1003 -e HOME=/tmp --memory 64g --cpus 48 \
    -v /tank/blender:/work -w $WORKDIR --entrypoint /blender/blender \"\$IMG\" \
    -b --factory-startup --python-exit-code 1 $ARGS"
RC=$?
set -e
if [ -n "$JOB" ]; then
  rsync -a --update "$HOST:/tank/blender/jobs/$NAME/" "$JOB"/
fi
exit $RC
