]> vilimpoc.org git repositories - dotfiles/blobdiff - setup-windows.bat
dotfiles: stop the UAC launch line mangling its own arguments
[dotfiles] / setup-windows.bat
index 1d202afd260adbed163662149bdce5c4d9645761..250d4cbb0b128aa076e48fea67a6e4a5d5d8f648 100644 (file)
@@ -7,16 +7,45 @@
 @rem --- Non-admin (per-user) winget installs ---\r
 winget install Anthropic.ClaudeCode\r
 winget install Git.Git\r
+winget install Microsoft.DotNet.SDK.10\r
 winget install Microsoft.PowerShell Microsoft.Sysinternals.ProcessExplorer Microsoft.Sysinternals.ProcessMonitor Microsoft.Sysinternals.SDelete Microsoft.VisualStudioCode Microsoft.WindowsTerminal\r
+winget install Oracle.VirtualBox\r
 winget install Python.Python.3.13\r
 winget install WinMerge.WinMerge\r
-winget install WiXToolset.WiXCLI\r
 \r
 @rem OpenCppCoverage: native (PE) line coverage for the C++ binaries. run-coverage-occ.py drives the\r
 @rem pytest suite under it to produce an HTML report (the binaries under test build with PDBs,\r
 @rem which it reads). The installer elevates via UAC.\r
 winget install OpenCppCoverage.OpenCppCoverage\r
 \r
+@rem --- WiX 5.0.2, pinned on purpose ---\r
+@rem WiX packages our proprietary software into MSIs, and the version is pinned to keep that\r
+@rem free of a fee. 5.0.2 is the last release distributed under the Microsoft Reciprocal\r
+@rem License alone. From 6.0 onward the package also carries OSMFEULA.txt, an Open Source\r
+@rem Maintenance Fee agreement: a monthly fee owed by anyone who uses the PREBUILT BINARIES\r
+@rem as part of revenue-generating activity and has annual gross revenue >= US$10,000.\r
+@rem\r
+@rem It is a fee for the binaries, not a restriction on what we ship - MS-RL is file-scoped\r
+@rem and never reached the MSIs WiX builds, under any version - but 5.0.2 owes nothing.\r
+@rem The 6.x/7.x SOURCE is still MS-RL too, so self-compiling is another way out; a pin is\r
+@rem the cheaper one. This replaces `winget install WiXToolset.WiXCLI`, which has no version\r
+@rem selector and so installs the latest (7.0.0 today, EULA and all).\r
+@rem\r
+@rem PIN THE MSBUILD SIDE TOO. A .wixproj referencing WixToolset.Sdk without a version\r
+@rem resolves to the latest - 7.x, same EULA - and nothing here constrains it. Pin it in the\r
+@rem project: <Project Sdk="WixToolset.Sdk/5.0.2">.\r
+@rem\r
+@rem dotnet.exe is called by full path: winget put the SDK on the machine PATH a few lines\r
+@rem ago, but this cmd session inherited its environment before that and cannot see it.\r
+@rem install-then-update is for re-runs - install fails once the tool is there, and update\r
+@rem then holds it at exactly 5.0.2 - which keeps this script idempotent like the rest.\r
+set "DOTNET_EXE=%ProgramFiles%\dotnet\dotnet.exe"\r
+"%DOTNET_EXE%" tool install --global wix --version 5.0.2 || "%DOTNET_EXE%" tool update --global wix --version 5.0.2\r
+\r
+@rem Report what the pin actually produced. By full path again, and because the shim lands in\r
+@rem a directory this session's PATH predates: expect "5.0.2+<commit>", not 7.x.\r
+"%USERPROFILE%\.dotnet\tools\wix.exe" --version\r
+\r
 @rem ---------------------------------------------------------------------------\r
 @rem No package manager needed for the Windows build\r
 @rem\r
@@ -27,10 +56,25 @@ winget install OpenCppCoverage.OpenCppCoverage
 @rem --- Elevated installs (VS2022, WDK, system tools) ---\r
 @rem The elevated script runs in its own window and logs to setup-windows-uac.log.\r
 @rem -PassThru + $p.ExitCode propagates its real exit code back through to ERRORLEVEL.\r
+@rem\r
+@rem -TraceUser passes YOU across the UAC boundary. Accepting that prompt with an\r
+@rem administrator's credentials runs the elevated half AS that administrator, so\r
+@rem it cannot see whose box this is; the account named here is the one it grants\r
+@rem non-elevated ETW collection rights to (xperf / wpr without a UAC prompt).\r
+@rem\r
+@rem The two values go through the environment, and the quotes the child needs\r
+@rem around them are built in PowerShell as [char]34, so the command line below\r
+@rem contains no embedded quote characters at all. Writing them inline as ""..""\r
+@rem works for ONE argument and quietly breaks at two: the quote-state parsing\r
+@rem swallows everything after the first into the -File value, and the elevated\r
+@rem PowerShell dies with "failed because the file does not have a '.ps1'\r
+@rem extension" and exit code -196608 (0xFFFD0000) before it can log a thing.\r
 set "UAC_LOG=%~dp0setup-windows-uac.log"\r
 if exist "%UAC_LOG%" del "%UAC_LOG%"\r
+set "UAC_SCRIPT=%~dp0setup-windows-with-uac.ps1"\r
+set "UAC_TRACE_USER=%USERDOMAIN%\%USERNAME%"\r
 \r
-powershell -NoProfile -Command "$p = Start-Process powershell -Verb RunAs -ArgumentList '-NoProfile','-ExecutionPolicy','Bypass','-File','""%~dp0setup-windows-with-uac.ps1""' -Wait -PassThru; exit $p.ExitCode"\r
+powershell -NoProfile -Command "$q = [char]34; $p = Start-Process powershell -Verb RunAs -ArgumentList '-NoProfile','-ExecutionPolicy','Bypass','-File',($q + $env:UAC_SCRIPT + $q),'-TraceUser',($q + $env:UAC_TRACE_USER + $q) -Wait -PassThru; exit $p.ExitCode"\r
 set "UAC_RC=%ERRORLEVEL%"\r
 \r
 @rem --- Surface the elevated session's output (its window has already closed) ---\r