3 @rem ---------------------------------------------------------------------------
\r
4 @rem setup-windows.bat - provision a fresh Windows box for BlockBox development
\r
5 @rem ---------------------------------------------------------------------------
\r
7 @rem --- Non-admin (per-user) installs + git config ---
\r
8 winget install Anthropic.ClaudeCode
\r
9 winget install Git.Git
\r
10 winget install Microsoft.PowerShell Microsoft.Sysinternals.ProcessExplorer Microsoft.Sysinternals.ProcessMonitor Microsoft.Sysinternals.SDelete Microsoft.VisualStudioCode Microsoft.WindowsTerminal
\r
11 winget install Python.Python.3.13
\r
12 winget install WinMerge.WinMerge
\r
13 winget install WiXToolset.WiXCLI
\r
15 @rem OpenCppCoverage: native (PE) line coverage for the C++ binaries. run-coverage-occ.py drives the
\r
16 @rem pytest suite under it to produce an HTML report (BlockBox + the sandbox DLLs build with PDBs,
\r
17 @rem which it reads). The installer elevates via UAC.
\r
18 winget install OpenCppCoverage.OpenCppCoverage
\r
20 @rem --- Add WinMerge to the user PATH (persists to the HKCU environment) ---
\r
21 @rem Runs non-elevated, so it updates THIS user's PATH (the elevated script runs
\r
22 @rem as a different account). Idempotent: only appends if not already present.
\r
23 powershell -NoProfile -Command "$c = @((Join-Path $env:ProgramFiles 'WinMerge'), (Join-Path ${env:ProgramFiles(x86)} 'WinMerge'), (Join-Path $env:LOCALAPPDATA 'Programs\WinMerge')); $d = $c | Where-Object { Test-Path (Join-Path $_ 'WinMergeU.exe') } | Select-Object -First 1; if (-not $d) { Write-Warning 'WinMerge not found; user PATH unchanged.'; exit 0 }; $u = [Environment]::GetEnvironmentVariable('Path','User'); if (-not $u) { $u = '' }; if (($u -split ';') -notcontains $d) { $new = if ($u.Trim()) { $u.TrimEnd(';') + ';' + $d } else { $d }; [Environment]::SetEnvironmentVariable('Path', $new, 'User'); Write-Host ('Added ' + $d + ' to user PATH (restart your shell to pick it up).') } else { Write-Host ($d + ' already in user PATH.') }"
\r
25 @rem --- BinSkim (binary hardening analyzer) - per-user install, no admin needed ---
\r
26 @rem BinSkim checks the exact mitigations we enable in CMakeLists.txt (CFG/XFG, CET,
\r
27 @rem ASLR/HighEntropyVA, DEP, /GS, stack cookies, DEPENDENTLOADFLAG, etc.). The
\r
28 @rem Microsoft.CodeAnalysis.BinSkim NuGet package ships a self-contained win-x64
\r
29 @rem build, so this needs no .NET SDK/runtime: download the .nupkg (a zip), extract
\r
30 @rem the win-x64 tool folder to %LOCALAPPDATA%\Programs\BinSkim, and add it to the
\r
31 @rem user PATH. After restarting the shell: binskim analyze path\to\BlockBox.exe
\r
32 @rem A failure here only warns (exit 0) so it never aborts the rest of provisioning.
\r
33 powershell -NoProfile -Command "try { $ErrorActionPreference='Stop'; [Net.ServicePointManager]::SecurityProtocol=[Net.SecurityProtocolType]::Tls12; $dest=Join-Path $env:LOCALAPPDATA 'Programs\BinSkim'; $tmp=Join-Path $env:TEMP ('binskim_'+[guid]::NewGuid().ToString('N')); New-Item -ItemType Directory -Force -Path $tmp | Out-Null; $zip=Join-Path $tmp 'binskim.zip'; Invoke-WebRequest -Uri 'https://www.nuget.org/api/v2/package/Microsoft.CodeAnalysis.BinSkim' -OutFile $zip; Expand-Archive -Path $zip -DestinationPath $tmp -Force; $exe=Get-ChildItem -Path $tmp -Recurse -Filter 'BinSkim.exe' | Where-Object { $_.FullName -match 'win-x64' } | Sort-Object FullName | Select-Object -Last 1; if (-not $exe) { throw 'BinSkim.exe (win-x64) not found in package.' }; if (Test-Path $dest) { Remove-Item -Recurse -Force $dest }; New-Item -ItemType Directory -Force -Path $dest | Out-Null; Copy-Item -Path (Join-Path $exe.Directory.FullName '*') -Destination $dest -Recurse -Force; Remove-Item -Recurse -Force $tmp; $u=[Environment]::GetEnvironmentVariable('Path','User'); if (-not $u) { $u='' }; if (($u -split ';') -notcontains $dest) { $new = if ($u.Trim()) { $u.TrimEnd(';')+';'+$dest } else { $dest }; [Environment]::SetEnvironmentVariable('Path',$new,'User'); Write-Host ('Added '+$dest+' to user PATH (restart your shell to pick it up).') } else { Write-Host ($dest+' already in user PATH.') }; Write-Host ('BinSkim installed to '+$dest) } catch { Write-Warning ('BinSkim install failed: '+$_.Exception.Message); exit 0 }"
\r
35 @rem --- Global git identity: EDIT THESE BEFORE RUNNING ---
\r
36 @rem Replace the placeholders with your own name and email, or comment the two
\r
37 @rem lines out and set your identity per-repository instead.
\r
38 git config --global user.name "PLACEHOLDER_NAME"
\r
39 git config --global user.email "PLACEHOLDER_EMAIL"
\r
40 git config --global core.sshcommand C:/Windows/System32/OpenSSH/ssh.exe
\r
42 @rem ---------------------------------------------------------------------------
\r
43 @rem No package manager needed for the Windows build
\r
46 @rem cd windows && cmake -B build -G "Visual Studio 17 2022" -A x64 && cmake --build build --config Release
\r
47 @rem ---------------------------------------------------------------------------
\r
49 @rem --- Elevated installs (VS2022, WDK, system tools) ---
\r
50 @rem The elevated script runs in its own window and logs to setup-windows-uac.log.
\r
51 @rem -PassThru + $p.ExitCode propagates its real exit code back through to ERRORLEVEL.
\r
52 set "UAC_LOG=%~dp0setup-windows-uac.log"
\r
53 if exist "%UAC_LOG%" del "%UAC_LOG%"
\r
55 powershell -NoProfile -Command "$p = Start-Process powershell -Verb RunAs -ArgumentList '-NoProfile','-ExecutionPolicy','Bypass','-File','""%~dp0setup-windows-with-uac.ps1""' -Wait -PassThru; exit $p.ExitCode"
\r
56 set "UAC_RC=%ERRORLEVEL%"
\r
58 @rem --- Surface the elevated session's output (its window has already closed) ---
\r
59 if exist "%UAC_LOG%" (
\r
61 echo ===== elevated setup log ^(%UAC_LOG%^) =====
\r
63 echo ===== end of elevated setup log =====
\r
65 echo [setup-windows] WARNING: no elevated log found at "%UAC_LOG%".
\r
66 echo [setup-windows] The elevated window may have been cancelled at the UAC prompt.
\r
69 if not "%UAC_RC%"=="0" (
\r
71 echo [setup-windows] ELEVATED SETUP FAILED ^(exit code %UAC_RC%^). See log above.
\r
75 echo [setup-windows] Elevated setup completed successfully.
\r
77 @rem Removed: this doesn't work as well as I hoped, maybe try again later
\r
78 @rem -- Install Headroom ---
\r
79 @rem py -m pip install "headroom-ai[all]"
\r
80 @rem npm install headroom-ai
\r
82 py -m pip install Pillow