From: Max Vilimpoc Date: Tue, 25 Aug 2026 10:45:40 +0000 (+0200) Subject: dotfiles: sync the Windows provisioning scripts X-Git-Url: https://vilimpoc.org/repos/dotfiles/commitdiff_plain/452f525c182a835867d0f229c821c41118d15808?hp=452f525c182a835867d0f229c821c41118d15808 dotfiles: sync the Windows provisioning scripts Three changes made in the other copy of these scripts, ported back so the two do not drift. The scripts are now byte-identical apart from a few naming lines and the one divergence that is deliberate: this copy keeps the PLACEHOLDER git identity, which the README tells you to edit before running. OpenSSH Server. Installed from the Windows on-demand capability (10/1809 and later), set Automatic, started, and reachable on all firewall profiles. That last part is the one worth having: the capability ships its own inbound rule, but it is Private-only on some images, and a VM's host-only or bridged adapter gets classified Public more often than not -- which presents as a service that is plainly running and plainly unreachable. That rule is adopted rather than duplicated. OpenSSH-Server-In-TCP is the name the capability itself uses, so a second rule beside it under another name would leave the narrow one in place and merely work around it, while one under the same name would collide. Widen it to all profiles if it exists, create it if it does not. One rule either way, under the name the platform expects. rsync. Windows ships the SSH transport and nothing to run over it, so `rsync host:path` has no remote end. The nuket/rsync-windows build is downloaded to C:\Tools\rsync and added to the machine PATH. Not "Program Files", because the fallback when PATH lookup fails is --rsync-path and a path with spaces is painful to quote through two shells. Machine rather than user PATH, because the remote end runs as `rsync --server ...` in a non-interactive session with no login shell: Win32-OpenSSH composes that environment from the registry, so a machine entry resolves there and does so for every account on the box. sshd is restarted after the write, since the running service holds the environment it started with. BinSkim now checks before it fetches. The .nupkg is a self-contained .NET build -- 141 MB at 4.4.9.11 -- and the old code downloaded it every run before working out it had nothing to do. The flat-container index is a few KB of JSON; take the newest non-prerelease and compare against nupkg-version.txt beside the installed tool. The download URL now interpolates the version we checked, rather than the v2 /package/ endpoint that redirects to whatever is newest right now. The PATH append moved out of the download branch so a lost PATH entry no longer costs 141 MB to repair. Both new sections warn rather than throw: a box that cannot run sshd should still finish provisioning the toolchain it came for. README picks up the remote-access notes, including the authorized_keys ACL requirement and the separate file that accounts in the Administrators group need. Co-Authored-By: Claude Opus 5 ---