Vestibule/packaging/vestibule.iss

119 lines
5.7 KiB
Plaintext

; vestibule.iss — Inno Setup script for the Vestibule Windows installer.
;
; Builds Vestibule-Setup-<version>.exe: stages usher.exe, the extension,
; configs, and provisioning scripts to C:\Program Files\Vestibule, adds
; Start Menu shortcuts for provisioning, and offers to launch the
; AssignedAccess provisioning wizard at the end.
;
; The installer STAGES files only — it never touches OS lockdown state.
; All OS-level configuration (kiosk account, AssignedAccess, autologon,
; policies) is done by scripts\provision-kiosk.ps1, which is fully
; parameterized for unattended deployment. See DEPLOYMENT.md.
;
; Build (local):
; cd helper && cargo build --release && cd ..
; packaging\build-installer.ps1
; Build (CI): .github/workflows/ci.yml, "package-windows" job.
;
; Inno Setup 6.x required.
#define MyAppName "Vestibule"
#define MyAppVersion "1.2.2"
#define MyAppPublisher "Jeremy Anderson"
#define MyAppURL "https://dcos.net"
#define MyAppExeVersion "1.2.2"
; Compile-time guard: fail with a clear message instead of shipping an
; installer without the helper binary.
#if !FileExists("..\helper\target\release\usher.exe")
#error usher.exe not found under helper\target\release. Build it first: cd helper; cargo build --release
#endif
[Setup]
AppId={{1DE48322-DE9E-43B3-B86B-41ABCD8EB585}
AppName={#MyAppName}
AppVersion={#MyAppVersion}
AppVerName={#MyAppName} {#MyAppVersion}
AppPublisher={#MyAppPublisher}
AppPublisherURL={#MyAppURL}
AppSupportURL={#MyAppURL}
DefaultDirName={autopf}\{#MyAppName}
DefaultGroupName={#MyAppName}
DisableProgramGroupPage=yes
LicenseFile=..\LICENSE
; Vestibule is a system-level kiosk product: install per-machine, elevated.
PrivilegesRequired=admin
ArchitecturesInstallIn64BitMode=x64compatible
OutputDir=Output
OutputBaseFilename=Vestibule-Setup-{#MyAppVersion}
SetupIconFile=icons\vestibule.ico
UninstallDisplayIcon={app}\bin\usher.exe
UninstallDisplayName={#MyAppName} {#MyAppVersion}
Compression=lzma2/max
SolidCompression=yes
WizardStyle=modern
; The installer is unsigned until a code-signing budget exists (see
; README "Honest limitations"). SmartScreen will warn; operators verify
; the hash from the release notes.
[Languages]
Name: "english"; MessagesFile: "compiler:Default.isl"
[Tasks]
Name: "provision"; Description: "Run the kiosk provisioning wizard after setup (configure AssignedAccess, kiosk account, autologon)"; Flags: unchecked
Name: "stagenativehost"; Description: "Also register usher as Native Messaging host for THIS user (developer mode; kiosk users get it automatically at logon)"
[Files]
Source: "..\helper\target\release\usher.exe"; DestDir: "{app}\bin"; Flags: ignoreversion
Source: "..\extension\*"; DestDir: "{app}\extension"; Flags: recursesubdirs createallsubdirs ignoreversion
Source: "..\config\*"; DestDir: "{app}\config"; Flags: ignoreversion
Source: "..\scripts\*.ps1"; DestDir: "{app}\scripts"; Flags: ignoreversion
Source: "..\scripts\*.py"; DestDir: "{app}\scripts"; Flags: ignoreversion
Source: "..\scripts\vestibule-kiosk.service.in"; DestDir: "{app}\scripts"; Flags: ignoreversion
Source: "..\docs\*"; DestDir: "{app}\docs"; Flags: recursesubdirs ignoreversion
Source: "..\DEPLOYMENT.md"; DestDir: "{app}"; Flags: ignoreversion
Source: "..\README.md"; DestDir: "{app}"; Flags: ignoreversion
Source: "..\QUICKSTART.md"; DestDir: "{app}"; Flags: ignoreversion
Source: "..\LICENSE"; DestDir: "{app}"; Flags: ignoreversion
[Icons]
Name: "{group}\Provision kiosk (run as admin)"; Filename: "powershell.exe"; Parameters: "-NoProfile -ExecutionPolicy Bypass -File ""{app}\scripts\provision-kiosk.ps1"""
Name: "{group}\Deprovision kiosk (run as admin)"; Filename: "powershell.exe"; Parameters: "-NoProfile -ExecutionPolicy Bypass -File ""{app}\scripts\deprovision-kiosk.ps1"""
Name: "{group}\Deployment guide"; Filename: "{app}\DEPLOYMENT.md"
Name: "{group}\README"; Filename: "{app}\README.md"
Name: "{group}\{cm:UninstallProgram,{#MyAppName}}"; Filename: "{uninstallexe}"
[Run]
; Developer-mode native host registration for the installing user
; (mirrors scripts/install-native-host.ps1 but from the staged binary).
Filename: "powershell.exe"; Parameters: "-NoProfile -ExecutionPolicy Bypass -Command ""if (-not (Test-Path \"$env:LOCALAPPDATA\Vestibule\usher.exe\")) { New-Item -ItemType Directory -Force -Path \"$env:LOCALAPPDATA\Vestibule\" | Out-Null; Copy-Item \"{app}\bin\usher.exe\" \"$env:LOCALAPPDATA\Vestibule\usher.exe\" }"""; Tasks: stagenativehost; Flags: runhidden; Description: "Register usher for this user"
; Provisioning wizard (elevated — the installer process is elevated).
Filename: "powershell.exe"; Parameters: "-NoProfile -ExecutionPolicy Bypass -File ""{app}\scripts\provision-kiosk.ps1"""; Tasks: provision; Flags: postinstall nowait skipifsilent; Description: "Run the kiosk provisioning wizard"
[UninstallDelete]
; The XPI is generated by provision-kiosk.ps1 after install.
Type: files; Name: "{app}\extension\vestibule.xpi"
Type: filesandordirs; Name: "{app}\Output"
[Code]
procedure CurUninstallStepChanged(CurUninstallStep: TUninstallStep);
var
ResultCode: Integer;
begin
if CurUninstallStep = usUninstall then
begin
if MsgBox('Also remove kiosk lockdown configuration?' + #13#10 + #13#10 +
'This runs deprovision-kiosk.ps1: removes AssignedAccess/' +
'Shell Launcher config, autologon, the kiosk shortcut, and ' +
'Vestibule policies. Choose Yes on kiosk machines, No to ' +
'keep OS configuration (e.g. shared dev boxes).',
mbConfirmation, MB_YESNO) = IDYES then
begin
Exec(ExpandConstant('{cmd}'),
'/C powershell.exe -NoProfile -ExecutionPolicy Bypass -File "' +
ExpandConstant('{app}') + '\scripts\deprovision-kiosk.ps1" -Quiet -RemoveKioskAccount',
'', SW_SHOW, ewWaitUntilTerminated, ResultCode);
end;
end;
end;