Repository navigation
Route MSIs correctly, verify payload hashes, honour or remove dead settings, make --status read-only - #54
Merged
Conversation
…ttings, make --status read-only MSI routing (#53). A Cimian-built MSI item with arguments was sent to sbin-installer, which read "/qn" as the package path. sbin-installer was also asked to install itself when it was published as SbinInstaller-*.msi rather than sbin-installer-*.msi. MSI arguments are msiexec arguments, so an item that has them goes to msiexec. So does the sbin-installer package, under any of its names. Payload integrity (#33). A manifest "hash" (SHA-256, optionally prefixed with "sha256:") is verified after download for every item type, preflight scripts included. A mismatch, or a hash that is not a SHA-256 digest, fails the item. Chocolatey no longer runs with --ignore-checksums; an item opts out with "ignoreChecksums": true and the run logs a warning. Dead settings (#27). DryRun is honoured the way --dry-run is: the run refuses. NetworkTimeout sets the manifest request timeout and the download stall timeout (default 120 s, clamped 10-600). DialogIcon reaches the dialog, EnableDialog=false turns the dialog off, and SilentMode and VerboseMode from policy or settings take effect. FollowRedirects and Reboot were never implemented. They are removed from the configuration, the ADMX and the GUI, and a value still set to true is logged as ignored. --status (#45). It runs before the elevation check, opens no session and never prompts. The CLI manifest is now asInvoker, so the read-only switches work for any user. An install run checks elevation itself: it relaunches elevated when it can, and exits 3 without prompting when there is no interactive console. --status and --clear-status also now use the real status.json path under ProgramData\ManagedBootstrap. Closes #53 Closes #33 Closes #27 Closes #45
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #53, #33, #27, #45.
MSI routing (#53)
argumentsare msiexec arguments, so an item that has any goes tomsiexec. Before, a Cimian-built MSI with/qnwent to sbin-installer, which read/qnas the package path.sbin-installer-*,SbinInstaller-*) or display name.InstallerRoutingand is unit-tested.Payload integrity (#33)
hash(SHA-256, optionally prefixed withsha256:) is verified after download for every item type, preflight scripts included. A mismatch, or a hash that is not SHA-256, fails the item.hashlog their SHA-256 at debug level.--ignore-checksumsis gone. An item can opt out with"ignoreChecksums": true, and the run logs a warning when it does.Configuration (#27)
--dry-run: refuses to run (exit 1). There is no simulated install.falseturns the dialog off, as NoDialog does.--status (#45)
asInvoker, so--status,--last-runand--versionwork for any user.runas.--statusand--clear-statusshowed and deletedProgramData\BootstrapMate\status.json. They now use the real path,ProgramData\ManagedBootstrap\status.json.Bugs caught by the signed test, fixed here
app.manifestcomment contained--, which is invalid inside an XML comment. The exe failed to start with 14001 (side-by-side configuration).ConfigManager.Instancewas built beforeRetiredSettingNameswas assigned, so every run threw. A regression test now covers it.Tests
64/64 unit tests pass. The signed x64 build was tested on an already-provisioned Windows 11 PC; machine state was restored afterwards.
Unelevated, stdin closed:
--status--last-run--version--url …(install)Elevated:
["/qn"]failed; the setupassistant item did not run.NetworkTimeout=15, stalled downloadReboot=1was logged as ignored.DryRun=1in machine settingsThe last change, warning only when a retired setting is true, was built and unit-tested but not re-run in the signed pass.