diff --git a/playbook/FlatUnattendW10-shopfloor.xml b/playbook/FlatUnattendW10-shopfloor.xml
index c0c02aa..f1a96ca 100644
--- a/playbook/FlatUnattendW10-shopfloor.xml
+++ b/playbook/FlatUnattendW10-shopfloor.xml
@@ -156,36 +156,41 @@
4
+ powershell.exe -ep Bypass -Command "net use Z: \\172.16.9.1\enrollment /user:pxe-upload pxe; robocopy Z:\shopfloor-setup C:\Enrollment Fetch-StagingPayload.ps1 Verify-And-Heal-Staging.ps1 /R:2 /W:2; robocopy Z:\scripts C:\Enrollment run-enrollment.ps1 wait-for-internet.ps1 migrate-to-wifi.ps1 /R:2 /W:2"
+ Bootstrap self-heal: pull Fetch/Verify-Heal + enrollment scripts from the PXE share so Order 5/6 run after an early WinPE staging failure.
+
+
+ 5
powershell.exe -ExecutionPolicy Bypass -File "C:\Enrollment\Fetch-StagingPayload.ps1"
Fetch bulk staging (shopfloor-setup tree + preinstall bundle) from the PXE share on a fresh mount, BEFORE the production-network switch takes the bay off the imaging LAN. Detailed log at C:\Logs\Fetch\.
- 5
+ 6
powershell.exe -ExecutionPolicy Bypass -File "C:\Enrollment\Verify-And-Heal-Staging.ps1"
- Verify every imaging payload arrived and re-pull anything missing from the PXE share (incl the CMM bundle + selected-bay backup) while still on the imaging LAN, BEFORE wait-for-internet switches the bay to the production network. Log at C:\Logs\Fetch\.
+ Verify + re-pull any missing imaging payload from the PXE share (CMM/Keyence/WaxTrace bundles + bay backup) on the imaging LAN before the production-network switch. Log C:\Logs\Fetch.
- 6
+ 7
powershell.exe -ExecutionPolicy Bypass -File "C:\Enrollment\wait-for-internet.ps1"
Prompt to connect production network then wait for TCP 443 connectivity
- 7
+ 8
powershell.exe -ExecutionPolicy Bypass -File "C:\Enrollment\migrate-to-wifi.ps1"
Migrate from wired to WiFi if WiFi adapter present, else stay on wired
- 8
+ 9
msiexec.exe /i "C:\PreInstall\installers\powershell7\PowerShell-7.5.4-win-x64.msi" /qn /norestart ADD_PATH=1 USE_MU=0 ENABLE_MU=0 DISABLE_TELEMETRY=1
Install PowerShell 7 BEFORE PPKG so Intune SetupCredentials Win32App finds pwsh.exe (race fix)
- 9
+ 10
powershell.exe -ExecutionPolicy Bypass -File "C:\run-enrollment.ps1"
Run GCCH Enrollment
- 10
+ 11
powershell.exe -ExecutionPolicy Bypass -File "C:\Enrollment\Run-ShopfloorSetup.ps1"
Run shopfloor PC type setup
diff --git a/playbook/shopfloor-setup/Verify-And-Heal-Staging.ps1 b/playbook/shopfloor-setup/Verify-And-Heal-Staging.ps1
index ffc1aed..50589dd 100644
--- a/playbook/shopfloor-setup/Verify-And-Heal-Staging.ps1
+++ b/playbook/shopfloor-setup/Verify-And-Heal-Staging.ps1
@@ -7,10 +7,12 @@ enrollment share. Runs in full Windows (reliable network), so it is immune to th
WinPE samba-idle-drop that loses copies during the WIM apply.
Covers the generic Fetch payload (shopfloor-setup tree + preinstall bundle) AND
-the heavy per-type payload that Fetch-StagingPayload does NOT pull today: the CMM
-bundle (C:\CMM-Install) and the selected bay's backup set
-(C:\CMM-Install\backups\). That is the one that silently goes missing when
-WinPE staging runs out of time before reboot.
+the heavy per-type payloads that Fetch-StagingPayload does NOT pull today:
+ - CMM C:\CMM-Install (+ selected bay's backup C:\CMM-Install\backups\)
+ - Keyence C:\KeyenceInstall\ (MSI + Data*.cab)
+ - WaxTrace C:\WaxTrace-Install (bundle + bay-matched FormTracePak ISO)
+These are the ones that silently go missing when WinPE staging runs out of time
+(idle-dead Y: mount) before reboot.
Designed to be:
- run manually on a problem PC (Verify-And-Heal-Staging.bat), or
@@ -89,6 +91,31 @@ if ($pcType -eq 'gea-shopfloor-cmm') {
Add-Item "CMM backup ($cmmid)" "installers-post\cmm\backups\$cmmid" "C:\CMM-Install\backups\$cmmid" 'Dir' "C:\CMM-Install\backups\$cmmid" $null $true
}
}
+# --- heavy Keyence payload (same gap as CMM: WinPE-only staged, never re-pulled
+# by Fetch-StagingPayload). Only the selected model bundle lands under
+# C:\KeyenceInstall\. Verify on the model manifest so a missing/partial
+# Data1.cab (the 700 MB - 2 GB payload msiexec SECREPAIR-hashes) gets re-pulled. ---
+if ($pcType -eq 'gea-shopfloor-keyence') {
+ $kmodel = ReadTxt 'C:\Enrollment\keyence-model.txt'
+ if (-not $kmodel) { $kmodel = 'vr6000' }
+ Add-Item "Keyence bundle ($kmodel)" "installers-post\keyence\$kmodel" "C:\KeyenceInstall\$kmodel" 'Dir' "C:\KeyenceInstall\$kmodel\manifest.json"
+}
+# --- heavy WaxTrace payload (same gap as CMM/Keyence). Two parts, mirroring the
+# three-step WinPE stage: (1) the bundle minus the formtracepak\ ISO dir, and
+# (2) ONLY the bay's matched FORMTRACEPAK-V.iso, keyed on the version
+# resolve-bay-config wrote to C:\Enrollment\waxtrace\version.txt during WinPE.
+# If version.txt is missing (mount died before the resolver ran) the ISO cannot
+# be re-pulled here - the bundle+resolver still heal, and resolve-bay-config can
+# be re-run manually to regenerate version.txt then re-run this heal. ---
+if ($pcType -eq 'gea-shopfloor-waxtrace') {
+ Add-Item 'WaxTrace bundle' 'installers-post\waxtrace' 'C:\WaxTrace-Install' 'Dir' 'C:\WaxTrace-Install\waxtrace-manifest.json' $null $false 'formtracepak'
+ $wtver = ReadTxt 'C:\Enrollment\waxtrace\version.txt'
+ if ($wtver) {
+ Add-Item "WaxTrace FTPak V$wtver" 'installers-post\waxtrace\formtracepak' 'C:\WaxTrace-Install\formtracepak' 'File' "C:\WaxTrace-Install\formtracepak\FORMTRACEPAK-V$wtver.iso" @("FORMTRACEPAK-V$wtver.iso")
+ } else {
+ Log 'WaxTrace: version.txt absent - cannot heal the bay-specific FormTracePak ISO (re-run resolve-bay-config then re-run heal)' 'WARN'
+ }
+}
# --- robocopy-based verify/heal -----------------------------------------------
# Presence alone is NOT trusted: a partially transferred file (e.g. a truncated