feat(windows-installer): move driver + web install into the host exe (ASCII root fix)
apple / swift (push) Successful in 1m0s
apple / screenshots (push) Successful in 5m16s
windows-host / package (push) Successful in 6m25s
ci / rust (push) Failing after 28s
ci / web (push) Successful in 53s
ci / docs-site (push) Successful in 1m1s
android / android (push) Successful in 3m21s
deb / build-publish (push) Successful in 2m31s
decky / build-publish (push) Successful in 11s
docker / build-push (--build-arg FEDORA_VERSION=44, ci, ci/fedora-rpm.Dockerfile, punktfunk-fedora44-rpm) (push) Successful in 5s
docker / build-push (., web/Dockerfile, punktfunk-web) (push) Successful in 5s
docker / build-push (ci, ci/fedora-rpm.Dockerfile, punktfunk-fedora-rpm) (push) Successful in 4s
docker / build-push (ci, ci/rust-ci.Dockerfile, punktfunk-rust-ci) (push) Successful in 6s
docker / build-push (docs-site, docs-site/Dockerfile, punktfunk-docs) (push) Successful in 4s
ci / bench (push) Successful in 4m39s
rpm / build-publish (bazzite, punktfunk-fedora-rpm) (push) Successful in 9m2s
rpm / build-publish (fedora-44, punktfunk-fedora44-rpm) (push) Successful in 8m50s
docker / deploy-docs (push) Successful in 17s

Port the three install-time PowerShell *files* (install-pf-vdisplay.ps1,
install-gamepad-drivers.ps1, web-setup.ps1) into punktfunk-host.exe subcommands:
`driver install [--gamepad] --dir <stage>` and `web setup --app-dir <app>
[--password-file <f>]` (windows/install.rs).

Why: PowerShell 5.1 reads a BOM-less .ps1 FILE in the machine ANSI codepage, so a
stray non-ASCII byte mis-decodes and aborts on a non-English box - exactly how the
pf-vdisplay driver install silently failed. A compiled subcommand drives the same
external tools (certutil/pnputil/nefconc/schtasks/netsh/icacls) as fixed string
literals, with no file-codepage surface. (The .iss's INLINE -Command PowerShell is a
command-line string, not a file read, so it's unaffected and stays.)

- windows/install.rs: faithful port - cert trust, gated nefconc node create + pnputil
  for pf-vdisplay; pnputil per-inf for gamepads; web-password ACL, the PunktfunkWeb task
  (generated UTF-16 XML), firewall rule, start. Best-effort (a hiccup warns, never aborts).
- punktfunk-host.iss [Run]: call the exe instead of `powershell -File`; drop the
  web-setup.ps1 staging + WebSetup define; WebSetupParams emits --app-dir/--password-file.
- pack-host-installer.ps1: stop copying the three install scripts into the stages.
- delete the three .ps1 files.

The `mod install;` + dispatch arms in main.rs landed in the preceding docs commit
(swept up by a concurrent commit); this commit adds the module + installer wiring.
CI-compile-validated via windows-host; the install path is on-glass-validated on the
next canary install (the test box is offline).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-06-26 16:43:18 +00:00
parent 7b99b41ede
commit 125a51d81d
6 changed files with 411 additions and 263 deletions
-110
View File
@@ -1,110 +0,0 @@
<#
Provision the punktfunk web console after the host installer has laid down its payload
({app}\web\.output, {app}\bun\bun.exe, {app}\web\web-run.cmd). Invoked elevated from the
installer's [Run] section; idempotent (safe to re-run on upgrade).
1. Sets the console login password file %ProgramData%\punktfunk\web-password
(PUNKTFUNK_UI_PASSWORD=...), ACL'd to Administrators + SYSTEM only:
- if -PasswordFile points at a non-empty temp file (a FRESH install collected one on the
wizard page), use that;
- else if the file already exists (UPGRADE), keep it untouched;
- else generate a random one (fallback, so the console never boots auth-misconfigured).
2. Registers the PunktfunkWeb scheduled task: at boot, as SYSTEM/Highest, restart-on-failure,
no execution time limit (a long-running server), running {app}\web\web-run.cmd.
3. Opens inbound TCP 3000 (the console port) on all profiles.
4. Waits briefly for the host's mgmt token, then starts the task.
The mgmt bearer token is NOT managed here - the host owns %ProgramData%\punktfunk\mgmt-token
(crates/punktfunk-host/src/mgmt_token.rs writes it on `serve`); web-run.cmd sources it.
#>
[CmdletBinding()]
param(
[Parameter(Mandatory = $true)][string]$AppDir, # the installer's {app}
[string]$PasswordFile # temp file with the chosen password (fresh install)
)
$ErrorActionPreference = 'Stop'
$TaskName = 'PunktfunkWeb'
$dataDir = Join-Path $env:ProgramData 'punktfunk'
$pwFile = Join-Path $dataDir 'web-password'
$tokenFile = Join-Path $dataDir 'mgmt-token'
New-Item -ItemType Directory -Force -Path $dataDir | Out-Null
function New-RandomPassword {
# URL/shell-safe (no /+=) so it's a clean env-file value and cmd-token, like scripts/web-init.sh.
$bytes = New-Object byte[] 24
([System.Security.Cryptography.RandomNumberGenerator]::Create()).GetBytes($bytes)
$s = [Convert]::ToBase64String($bytes) -replace '[/+=]', ''
return $s.Substring(0, [Math]::Min(20, $s.Length))
}
function Stop-WebConsole {
# On an upgrade a console is already running. Stop + reap it before re-registering so (a) the new
# task can bind :3000 (else the old server keeps it and the new one restart-loops on EADDRINUSE) and
# (b) the installer can overwrite .output / web-run.cmd / bun.exe (a held file blocks the copy). A
# prior install may have run a DIFFERENT runtime (node vs bun), so kill by the script it serves AND
# by the :3000 owner - the latter is runtime-agnostic and future-proofs the next runtime swap.
Stop-ScheduledTask -TaskName $TaskName -ErrorAction SilentlyContinue
Get-CimInstance Win32_Process -Filter "Name='bun.exe' OR Name='node.exe'" -ErrorAction SilentlyContinue |
Where-Object { $_.CommandLine -match 'index\.mjs' } |
ForEach-Object { Stop-Process -Id $_.ProcessId -Force -ErrorAction SilentlyContinue }
Get-NetTCPConnection -LocalPort 3000 -State Listen -ErrorAction SilentlyContinue |
Select-Object -ExpandProperty OwningProcess -Unique |
ForEach-Object { Stop-Process -Id $_ -Force -ErrorAction SilentlyContinue }
Start-Sleep -Seconds 1
}
# --- 1. login password -----------------------------------------------------------------------
$password = $null
if ($PasswordFile -and (Test-Path -LiteralPath $PasswordFile)) {
$password = (Get-Content -LiteralPath $PasswordFile -Raw).Trim()
}
if (-not $password) {
if (Test-Path -LiteralPath $pwFile) {
Write-Host "keeping existing web console password ($pwFile)"
}
else {
$password = New-RandomPassword
Write-Host "no password supplied - generated a random web console password"
}
}
if ($password) {
# LF, no BOM (UTF8) so web-run.cmd's `for /f` reads a clean value.
[IO.File]::WriteAllText($pwFile, "PUNKTFUNK_UI_PASSWORD=$password`n")
# Lock it down: drop inheritance, grant only Administrators (S-1-5-32-544) + SYSTEM (S-1-5-18).
& icacls $pwFile /inheritance:r /grant:r '*S-1-5-32-544:F' '*S-1-5-18:F' | Out-Null
}
# --- 2. PunktfunkWeb scheduled task ----------------------------------------------------------
Stop-WebConsole # reap any running (possibly old-runtime) console before re-registering (upgrade-safe)
$cmd = Join-Path $AppDir 'web\web-run.cmd'
if (-not (Test-Path -LiteralPath $cmd)) { throw "web launcher missing: $cmd" }
$action = New-ScheduledTaskAction -Execute $cmd
$trigger = New-ScheduledTaskTrigger -AtStartup
$principal = New-ScheduledTaskPrincipal -UserId 'SYSTEM' -LogonType ServiceAccount -RunLevel Highest
# RestartCount/Interval cover transient crashes + the brief post-install race before the host has
# written the mgmt token (web-run.cmd exits non-zero until then). No time limit: it's a server.
$settings = New-ScheduledTaskSettingsSet -AllowStartIfOnBatteries -DontStopIfGoingOnBatteries `
-StartWhenAvailable -RestartInterval (New-TimeSpan -Minutes 1) -RestartCount 10 `
-ExecutionTimeLimit (New-TimeSpan -Seconds 0)
Register-ScheduledTask -TaskName $TaskName -Action $action -Trigger $trigger -Principal $principal `
-Settings $settings -Description 'punktfunk web management console (Nitro SSR on bun, :3000)' `
-Force | Out-Null
Write-Host "registered scheduled task $TaskName -> $cmd"
# --- 3. firewall: inbound TCP 3000 -----------------------------------------------------------
try {
$fwName = 'PunktfunkWeb-TCP-3000'
Get-NetFirewallRule -Name $fwName -ErrorAction SilentlyContinue | Remove-NetFirewallRule -ErrorAction SilentlyContinue
New-NetFirewallRule -Name $fwName -DisplayName 'punktfunk web console (TCP 3000)' `
-Direction Inbound -Action Allow -Protocol TCP -LocalPort 3000 -Profile Any | Out-Null
Write-Host "firewall: allowed inbound TCP 3000"
}
catch { Write-Warning "could not add the firewall rule for TCP 3000: $($_.Exception.Message)" }
# --- 4. wait for the host's mgmt token, then start -------------------------------------------
# The host service was installed+started just before this; give it a moment to write the token so
# the first start serves immediately (otherwise restart-on-failure picks it up within a minute).
for ($i = 0; $i -lt 30 -and -not (Test-Path -LiteralPath $tokenFile); $i++) { Start-Sleep -Seconds 1 }
Start-ScheduledTask -TaskName $TaskName
Write-Host "started $TaskName (console on http://<host-ip>:3000)"