; vestibule.iss — Inno Setup script for the Vestibule Windows installer. ; ; Builds Vestibule-Setup-.exe: stages usher.exe, the extension, ; configs, and provisioning scripts to C:\Program Files\Vestibule, adds ; Start Menu shortcuts for provisioning, and offers to launch the ; AssignedAccess provisioning wizard at the end. ; ; The installer STAGES files only — it never touches OS lockdown state. ; All OS-level configuration (kiosk account, AssignedAccess, autologon, ; policies) is done by scripts\provision-kiosk.ps1, which is fully ; parameterized for unattended deployment. See DEPLOYMENT.md. ; ; Build (local): ; cd helper && cargo build --release && cd .. ; packaging\build-installer.ps1 ; Build (CI): .github/workflows/ci.yml, "package-windows" job. ; ; Inno Setup 6.x required. #define MyAppName "Vestibule" #define MyAppVersion "1.2.2" #define MyAppPublisher "Jeremy Anderson" #define MyAppURL "https://dcos.net" #define MyAppExeVersion "1.2.2" ; Compile-time guard: fail with a clear message instead of shipping an ; installer without the helper binary. #if !FileExists("..\helper\target\release\usher.exe") #error usher.exe not found under helper\target\release. Build it first: cd helper; cargo build --release #endif [Setup] AppId={{1DE48322-DE9E-43B3-B86B-41ABCD8EB585} AppName={#MyAppName} AppVersion={#MyAppVersion} AppVerName={#MyAppName} {#MyAppVersion} AppPublisher={#MyAppPublisher} AppPublisherURL={#MyAppURL} AppSupportURL={#MyAppURL} DefaultDirName={autopf}\{#MyAppName} DefaultGroupName={#MyAppName} DisableProgramGroupPage=yes LicenseFile=..\LICENSE ; Vestibule is a system-level kiosk product: install per-machine, elevated. PrivilegesRequired=admin ArchitecturesInstallIn64BitMode=x64compatible OutputDir=Output OutputBaseFilename=Vestibule-Setup-{#MyAppVersion} SetupIconFile=icons\vestibule.ico UninstallDisplayIcon={app}\bin\usher.exe UninstallDisplayName={#MyAppName} {#MyAppVersion} Compression=lzma2/max SolidCompression=yes WizardStyle=modern ; The installer is unsigned until a code-signing budget exists (see ; README "Honest limitations"). SmartScreen will warn; operators verify ; the hash from the release notes. [Languages] Name: "english"; MessagesFile: "compiler:Default.isl" [Tasks] Name: "provision"; Description: "Run the kiosk provisioning wizard after setup (configure AssignedAccess, kiosk account, autologon)"; Flags: unchecked Name: "stagenativehost"; Description: "Also register usher as Native Messaging host for THIS user (developer mode; kiosk users get it automatically at logon)" [Files] Source: "..\helper\target\release\usher.exe"; DestDir: "{app}\bin"; Flags: ignoreversion Source: "..\extension\*"; DestDir: "{app}\extension"; Flags: recursesubdirs createallsubdirs ignoreversion Source: "..\config\*"; DestDir: "{app}\config"; Flags: ignoreversion Source: "..\scripts\*.ps1"; DestDir: "{app}\scripts"; Flags: ignoreversion Source: "..\scripts\*.py"; DestDir: "{app}\scripts"; Flags: ignoreversion Source: "..\scripts\vestibule-kiosk.service.in"; DestDir: "{app}\scripts"; Flags: ignoreversion Source: "..\docs\*"; DestDir: "{app}\docs"; Flags: recursesubdirs ignoreversion Source: "..\DEPLOYMENT.md"; DestDir: "{app}"; Flags: ignoreversion Source: "..\README.md"; DestDir: "{app}"; Flags: ignoreversion Source: "..\QUICKSTART.md"; DestDir: "{app}"; Flags: ignoreversion Source: "..\LICENSE"; DestDir: "{app}"; Flags: ignoreversion [Icons] Name: "{group}\Provision kiosk (run as admin)"; Filename: "powershell.exe"; Parameters: "-NoProfile -ExecutionPolicy Bypass -File ""{app}\scripts\provision-kiosk.ps1""" Name: "{group}\Deprovision kiosk (run as admin)"; Filename: "powershell.exe"; Parameters: "-NoProfile -ExecutionPolicy Bypass -File ""{app}\scripts\deprovision-kiosk.ps1""" Name: "{group}\Deployment guide"; Filename: "{app}\DEPLOYMENT.md" Name: "{group}\README"; Filename: "{app}\README.md" Name: "{group}\{cm:UninstallProgram,{#MyAppName}}"; Filename: "{uninstallexe}" [Run] ; Developer-mode native host registration for the installing user ; (mirrors scripts/install-native-host.ps1 but from the staged binary). Filename: "powershell.exe"; Parameters: "-NoProfile -ExecutionPolicy Bypass -Command ""if (-not (Test-Path \"$env:LOCALAPPDATA\Vestibule\usher.exe\")) { New-Item -ItemType Directory -Force -Path \"$env:LOCALAPPDATA\Vestibule\" | Out-Null; Copy-Item \"{app}\bin\usher.exe\" \"$env:LOCALAPPDATA\Vestibule\usher.exe\" }"""; Tasks: stagenativehost; Flags: runhidden; Description: "Register usher for this user" ; Provisioning wizard (elevated — the installer process is elevated). Filename: "powershell.exe"; Parameters: "-NoProfile -ExecutionPolicy Bypass -File ""{app}\scripts\provision-kiosk.ps1"""; Tasks: provision; Flags: postinstall nowait skipifsilent; Description: "Run the kiosk provisioning wizard" [UninstallDelete] ; The XPI is generated by provision-kiosk.ps1 after install. Type: files; Name: "{app}\extension\vestibule.xpi" Type: filesandordirs; Name: "{app}\Output" [Code] procedure CurUninstallStepChanged(CurUninstallStep: TUninstallStep); var ResultCode: Integer; begin if CurUninstallStep = usUninstall then begin if MsgBox('Also remove kiosk lockdown configuration?' + #13#10 + #13#10 + 'This runs deprovision-kiosk.ps1: removes AssignedAccess/' + 'Shell Launcher config, autologon, the kiosk shortcut, and ' + 'Vestibule policies. Choose Yes on kiosk machines, No to ' + 'keep OS configuration (e.g. shared dev boxes).', mbConfirmation, MB_YESNO) = IDYES then begin Exec(ExpandConstant('{cmd}'), '/C powershell.exe -NoProfile -ExecutionPolicy Bypass -File "' + ExpandConstant('{app}') + '\scripts\deprovision-kiosk.ps1" -Quiet -RemoveKioskAccount', '', SW_SHOW, ewWaitUntilTerminated, ResultCode); end; end; end;