windows-host / package (push) Failing after 22s
windows-host / canary-manifest (push) Skipped
windows-host / winget-source (push) Skipped
ci / docs-site (push) Successful in 1m47s
ci / web (push) Successful in 1m53s
ci / rust-arm64 (push) Successful in 1m58s
docker / builders (--build-arg FEDORA_VERSION=44, ci/fedora-rpm.Dockerfile, punktfunk-fedora44-rpm, -f44) (push) Successful in 11s
docker / builders (ci/android-ci.Dockerfile, punktfunk-android-ci) (push) Successful in 9s
docker / builders (ci/arch-ci.Dockerfile, punktfunk-arch-ci) (push) Successful in 7s
docker / builders (ci/fedora-rpm.Dockerfile, punktfunk-fedora-rpm) (push) Successful in 7s
docker / builders (ci/rust-ci-noble.Dockerfile, punktfunk-rust-ci-noble) (push) Successful in 8s
docker / builders (ci/rust-ci.Dockerfile, punktfunk-rust-ci) (push) Successful in 6s
docker / apps (., web/Dockerfile, punktfunk-web) (push) Successful in 58s
apple / swift (push) Successful in 4m45s
deb / build-publish-client-arm64 (push) Successful in 3m28s
docker / apps (docs-site, docs-site/Dockerfile, punktfunk-docs) (push) Successful in 1m27s
deb / build-publish (push) Successful in 5m26s
docker / builders-arm64cross (push) Successful in 6s
android / android (push) Successful in 6m22s
docker / deploy-docs (push) Successful in 38s
ci / rust (push) Successful in 7m10s
deb / build-publish-host (push) Successful in 5m27s
arch / build-publish (push) Successful in 8m42s
rpm / build-publish (44, fedora-44, punktfunk-fedora44-rpm) (push) Successful in 16m58s
rpm / build-publish (43, bazzite, punktfunk-fedora-rpm) (push) Successful in 17m16s
apple / screenshots (push) Successful in 20m19s
Three silent console outages in one week (0x1 / 0xFFFFFFFF / 0x41306), each a different proximate cause of the same structural defect: the console's lifecycle was owned by Task Scheduler — one best-effort start per boot/logon/install, no retry on a plain non-zero exit, no watchdog — while the product already shipped a real supervisor. The service now supervises the console as a second child slot: plain session-0 spawn (suspended → own no-breakaway kill-on-close job → resume), started only once the host has written mgmt-token + cert.pem + key.pem (the cert race dies by construction), secrets read from their files at every respawn, bun's stdout finally captured in logs\web.log, doubling backoff 0.5s→60s that never gives up. Session switches never touch it; a service stop takes it down via the job. The PunktfunkWeb task is retired: web setup slims to password + legacy task delete + firewall, the 127-line web-run.cmd batch supervisor is deleted, an [InstallDelete] entry reaps the stale copy, and service install now sets SCM crash-recovery actions (restart 1s/5s/60s) since the console rides on the service process. StopBunRuntimes stays for the scripting runner + the one migrating upgrade. Design: punktfunk-planning design/windows-web-console-lifecycle.md Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
102 lines
4.9 KiB
Markdown
102 lines
4.9 KiB
Markdown
# Windows host build/deploy scripts
|
|
|
|
Helper scripts for the Windows host box (the RTX `.173` lab box, repo at
|
|
`C:\Users\Public\punktfunk-native`). Run them from the repo root in an **elevated** PowerShell.
|
|
|
|
## One-time: persist the build environment
|
|
|
|
```powershell
|
|
powershell -ExecutionPolicy Bypass -File scripts\windows\setup-build-env.ps1
|
|
```
|
|
|
|
Persists (Machine scope) the vars the host build needs (NVENC itself needs none — its entry
|
|
points are runtime-loaded from the driver's `nvEncodeAPI64.dll`):
|
|
|
|
| var | value | why |
|
|
| --- | --- | --- |
|
|
| `LIBCLANG_PATH` | `C:\Program Files\LLVM\bin` | bindgen (`libclang.dll`) |
|
|
| `CMAKE_POLICY_VERSION_MINIMUM` | `3.5` | `audiopus_sys` / cmake crates |
|
|
|
|
`FFMPEG_DIR` is **not** set — the `--features nvenc` build the RTX box uses does not link
|
|
libavcodec (that is only the `amf-qsv` feature). The VS C++ toolchain is loaded per-build via
|
|
`vcvars64.bat` (auto-discovered with `vswhere`).
|
|
|
|
## Rebuild + redeploy the host service
|
|
|
|
```powershell
|
|
powershell -ExecutionPolicy Bypass -File scripts\windows\deploy-host.ps1
|
|
```
|
|
|
|
Stops `PunktfunkHost`, backs up the current binary (`punktfunk-host.exe.bak`), builds
|
|
`--release -p punktfunk-host --features nvenc` from the current source, then restarts the
|
|
service on the new binary — **with automatic rollback** if the build fails or the new binary
|
|
won't start. The service is down only for the build duration.
|
|
|
|
## Web management console
|
|
|
|
On an **installed** host (the `setup.exe`) the console is set up automatically — no manual steps.
|
|
The installer bundles the built (self-contained, no-`node_modules`) `.output` server + a portable
|
|
bun; the **`PunktfunkHost` service supervises the console as its own child** (`bun
|
|
{app}\web\.output\server\index.mjs` on `:47992`, session 0, restarted on any exit, stdout in
|
|
`%ProgramData%\punktfunk\logs\web.log`), starting it as soon as the host has written its mgmt token
|
|
+ identity cert. `punktfunk-host.exe web setup` provisions the rest: it opens inbound TCP 47992 and
|
|
writes the login password to `%ProgramData%\punktfunk\web-password` (ACL'd to Administrators +
|
|
SYSTEM). The mgmt bearer token it proxies with is the host's own
|
|
`%ProgramData%\punktfunk\mgmt-token`. Browse `https://<host-ip>:47992` and log in with the password
|
|
the installer shows on its final page. To change it, edit `web-password` and restart the service
|
|
(`punktfunk-host service restart`) — or just kill the console's `bun.exe`; the supervisor respawns
|
|
it with the new value.
|
|
|
|
### Rebuild + restart the console (dev box)
|
|
|
|
```powershell
|
|
powershell -ExecutionPolicy Bypass -File scripts\windows\build-web.ps1
|
|
```
|
|
|
|
`bun install && bun run build` (Nitro `noExternals` -> a self-contained `.output`, no
|
|
`node_modules`/`.npmrc`), then swaps the fresh `.output` into `{app}\web` around a service
|
|
stop/start (the service's kill-on-close job is what unlocks the console's bun) and checks
|
|
`:47992/login`. Use this to iterate on the console against an installed host.
|
|
|
|
## Plugin/script runner
|
|
|
|
```powershell
|
|
powershell -ExecutionPolicy Bypass -File scripts\windows\build-scripting.ps1
|
|
powershell -ExecutionPolicy Bypass -File scripts\windows\build-scripting.ps1 -EnableTask
|
|
```
|
|
|
|
`bun install && bun build src/runner-cli.ts --target=bun` in `sdk\` -> one self-contained
|
|
`runner-cli.js` (effect + the SDK inlined; the operator's plugin `import()` stays a runtime import,
|
|
gated on the same `attempt=` check CI and the `.deb` builder use), then lays it out as
|
|
`<exe-dir>\scripting\runner-cli.js` + `scripting-run.cmd` with the bun runtime at `<exe-dir>\bun\bun.exe`.
|
|
|
|
**That layout is load-bearing.** `punktfunk-host plugins add/remove/list` forwards package ops to the
|
|
runner, and on Windows it resolves the runner *relative to the running exe* (`crates\punktfunk-host\src\plugins.rs`).
|
|
Since `deploy-host.ps1` runs the service out of `target\release`, a bundle sitting only in the
|
|
installed `{app}` leaves the freshly built exe reporting *"the plugin runner isn't installed"*. The
|
|
script deploys next to **every** host exe it finds - the built one and whatever the `PunktfunkHost`
|
|
service actually runs.
|
|
|
|
The `PunktfunkScripting` task is registered **disabled** (opt-in) by the installer, so the script
|
|
stages the bundle but does not silently enable it. Pass `-EnableTask` on a box you are validating
|
|
plugins on (equivalent to `punktfunk-host plugins enable`).
|
|
|
|
## Rebuild + redeploy everything
|
|
|
|
```powershell
|
|
powershell -ExecutionPolicy Bypass -File scripts\windows\deploy-all.ps1
|
|
powershell -ExecutionPolicy Bypass -File scripts\windows\deploy-all.ps1 -EnableScriptingTask
|
|
```
|
|
|
|
Thin wrapper: runs `deploy-host.ps1`, `build-web.ps1` then `build-scripting.ps1` in sequence — the
|
|
web console and plugin runner are **always** included, so the host binary and the runner bundle
|
|
never drift apart. If the host build/start fails, `deploy-host.ps1` rolls itself back and throws,
|
|
which stops this script before the later steps run.
|
|
|
|
## Typical flow after pulling new code
|
|
|
|
```powershell
|
|
git pull
|
|
powershell -ExecutionPolicy Bypass -File scripts\windows\deploy-all.ps1
|
|
```
|