CMM/DODA: enable on bays 4/10/11/12, fix PCTypes match, grant PreProcess ACL
Three fixes so DODA actually deploys on the four bays that need it:
- cmm-bay-config.csv: doda=yes for CMM4, CMM10, CMM11, CMM12 (was no on all
bays). Drives doda.txt -> startnet pc-subtype.txt=doda -> the cmm-doda path.
- cmm-manifest.json: DODA entry PCTypes "cmm-doda" -> "gea-shopfloor-cmm-doda".
The old value never matched: Test-PCTypeMatches builds the PC identity set as
{gea-shopfloor-cmm, gea-shopfloor-cmm-doda, CMM} (the alias of the cmm type is
bare CMM, no subtype variant), so "cmm-doda" was in no set and the entry was
silently skipped. Must be the exact Type-SubType string.
- Install-DODA.ps1: grant Users + Authenticated Users Full on C:\Apps\DODA\
PreProcess (icacls, SIDs, OI/CI inherit), applied every run. MergeFiles.exe
writes there as the locked-down operator; without it the merge step fails.
Not yet pushed to the SFLD/enrollment share (server unreachable at commit time).
Not smoke-tested - no pwsh available here; logic-traced only.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -39,6 +39,16 @@ if (-not (Test-Path $preProcess)) {
|
|||||||
Write-Host "Created $preProcess"
|
Write-Host "Created $preProcess"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# MergeFiles.exe writes into PreProcess\ at runtime AS THE LOCKED-DOWN OPERATOR,
|
||||||
|
# not admin. Without write access the GetDoDAFolder/merge step fails. Grant
|
||||||
|
# Users + Authenticated Users Full (object+container inherit). SIDs, not names,
|
||||||
|
# to stay locale-independent. Applied every run so it re-asserts after any
|
||||||
|
# lockdown pass that strips the ACE.
|
||||||
|
foreach ($sid in '*S-1-5-32-545','*S-1-5-11') { # BUILTIN\Users, NT AUTHORITY\Authenticated Users
|
||||||
|
& icacls $preProcess /grant "${sid}:(OI)(CI)F" /T /C 2>&1 | Out-Null
|
||||||
|
}
|
||||||
|
Write-Host "Granted Users + Authenticated Users Full on $preProcess"
|
||||||
|
|
||||||
if (Test-Path (Join-Path $installDir 'DovetailAnalysis.exe')) {
|
if (Test-Path (Join-Path $installDir 'DovetailAnalysis.exe')) {
|
||||||
Write-Host "DovetailAnalysis.exe verified present"
|
Write-Host "DovetailAnalysis.exe verified present"
|
||||||
exit 0
|
exit 0
|
||||||
|
|||||||
@@ -2,12 +2,12 @@ cmm_id,pcdmis_version,doda,part_group
|
|||||||
CMM1,2019,no,S:\CMM\CMM1\HPTCMM1
|
CMM1,2019,no,S:\CMM\CMM1\HPTCMM1
|
||||||
CMM2,2019,no,S:\CMM\CMM2\HPT
|
CMM2,2019,no,S:\CMM\CMM2\HPT
|
||||||
CMM3,2019,no,S:\CMM\CMM3\VENTURE_CMM3
|
CMM3,2019,no,S:\CMM\CMM3\VENTURE_CMM3
|
||||||
CMM4,2016,no,S:\CMM\CMM4\Spool
|
CMM4,2016,yes,S:\CMM\CMM4\Spool
|
||||||
CMM5,2019,no,S:\CMM\CMM5\BLISKCMM5
|
CMM5,2019,no,S:\CMM\CMM5\BLISKCMM5
|
||||||
CMM6,2019,no,S:\CMM\CMM6\BLISKCMM6
|
CMM6,2019,no,S:\CMM\CMM6\BLISKCMM6
|
||||||
CMM7,2019,no,S:\CMM\CMM7\VENTURE_CMM7
|
CMM7,2019,no,S:\CMM\CMM7\VENTURE_CMM7
|
||||||
CMM8,2019,no,S:\CMM\CMM8\Venture CMM8
|
CMM8,2019,no,S:\CMM\CMM8\Venture CMM8
|
||||||
CMM9,2019,no,S:\CMM\CMM9\BLISKCMM9
|
CMM9,2019,no,S:\CMM\CMM9\BLISKCMM9
|
||||||
CMM10,2016,no,S:\CMM\CMM10\Spool
|
CMM10,2016,yes,S:\CMM\CMM10\Spool
|
||||||
CMM11,2026,no,S:\CMM\CMM11\Spool
|
CMM11,2026,yes,S:\CMM\CMM11\Spool
|
||||||
CMM12,2026,no,S:\CMM\CMM12\Spool
|
CMM12,2026,yes,S:\CMM\CMM12\Spool
|
||||||
|
|||||||
|
@@ -67,9 +67,9 @@
|
|||||||
"DetectionPath": "HKLM:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{94f02b85-bbca-422e-9b8b-0c16a769eced}"
|
"DetectionPath": "HKLM:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{94f02b85-bbca-422e-9b8b-0c16a769eced}"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"_comment": "DODA - Dovetail Digital Analysis. Deployed as a flat file extract to C:\\Apps\\DODA\\. Only installed when doda.txt=yes (pc-subtype.txt=doda gates this via PCTypes).",
|
"_comment": "DODA - Dovetail Digital Analysis. Deployed as a flat file extract to C:\\Apps\\DODA\\. Only installed when doda.txt=yes -> startnet writes pc-subtype.txt=doda -> 09-Setup passes PCType=gea-shopfloor-cmm + PCSubType=doda -> matcher builds 'gea-shopfloor-cmm-doda'. PCTypes MUST be that exact Type-SubType string ('cmm-doda' never matched - the alias of gea-shopfloor-cmm is bare 'CMM', no subtype variant).",
|
||||||
"Name": "DODA",
|
"Name": "DODA",
|
||||||
"PCTypes": ["cmm-doda"],
|
"PCTypes": ["gea-shopfloor-cmm-doda"],
|
||||||
"Type": "PS1",
|
"Type": "PS1",
|
||||||
"Script": "Install-DODA.ps1",
|
"Script": "Install-DODA.ps1",
|
||||||
"DetectionMethod": "File",
|
"DetectionMethod": "File",
|
||||||
|
|||||||
Reference in New Issue
Block a user