Three fixes so DODA actually deploys on the four bays that need it:
- cmm-bay-config.csv: doda=yes for CMM4, CMM10, CMM11, CMM12 (was no on all
bays). Drives doda.txt -> startnet pc-subtype.txt=doda -> the cmm-doda path.
- cmm-manifest.json: DODA entry PCTypes "cmm-doda" -> "gea-shopfloor-cmm-doda".
The old value never matched: Test-PCTypeMatches builds the PC identity set as
{gea-shopfloor-cmm, gea-shopfloor-cmm-doda, CMM} (the alias of the cmm type is
bare CMM, no subtype variant), so "cmm-doda" was in no set and the entry was
silently skipped. Must be the exact Type-SubType string.
- Install-DODA.ps1: grant Users + Authenticated Users Full on C:\Apps\DODA\
PreProcess (icacls, SIDs, OI/CI inherit), applied every run. MergeFiles.exe
writes there as the locked-down operator; without it the merge step fails.
Not yet pushed to the SFLD/enrollment share (server unreachable at commit time).
Not smoke-tested - no pwsh available here; logic-traced only.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
59 lines
2.3 KiB
PowerShell
59 lines
2.3 KiB
PowerShell
# Install-DODA.ps1 - Extract DODA zip to C:\Apps\DODA\.
|
|
#
|
|
# Called by Install-FromManifest as a Type=PS1 entry. The zip is staged
|
|
# alongside this script in C:\CMM-Install\ by startnet.cmd.
|
|
|
|
$ErrorActionPreference = 'Continue'
|
|
|
|
$installDir = 'C:\Apps\DODA'
|
|
$zipPattern = 'doda_build*.zip'
|
|
$stagingRoot = Split-Path $PSScriptRoot -ErrorAction SilentlyContinue
|
|
if (-not $stagingRoot) { $stagingRoot = 'C:\CMM-Install' }
|
|
|
|
$zip = Get-ChildItem -Path $stagingRoot -Filter $zipPattern -File -ErrorAction SilentlyContinue | Select-Object -First 1
|
|
if (-not $zip) {
|
|
Write-Host "DODA zip not found in $stagingRoot (pattern: $zipPattern)"
|
|
exit 1
|
|
}
|
|
|
|
if (-not (Test-Path $installDir)) {
|
|
New-Item -Path $installDir -ItemType Directory -Force | Out-Null
|
|
}
|
|
|
|
Write-Host "Extracting $($zip.Name) to $installDir..."
|
|
try {
|
|
Expand-Archive -LiteralPath $zip.FullName -DestinationPath $installDir -Force -ErrorAction Stop
|
|
Write-Host "DODA extracted to $installDir"
|
|
} catch {
|
|
Write-Host "ERROR: Extract failed - $_"
|
|
exit 1
|
|
}
|
|
|
|
# MergeFiles.exe (cmm-utilities toolchain) reads C:\Apps\DODA\PreProcess\ as
|
|
# its working dir. The DODA zip extracts flat without it, so create it here -
|
|
# a missing PreProcess dir is the known cause of MergeFiles.GetDoDAFolder
|
|
# throwing DirectoryNotFoundException (see cmm-utilities dotNET event.txt).
|
|
$preProcess = Join-Path $installDir 'PreProcess'
|
|
if (-not (Test-Path $preProcess)) {
|
|
New-Item -Path $preProcess -ItemType Directory -Force | Out-Null
|
|
Write-Host "Created $preProcess"
|
|
}
|
|
|
|
# MergeFiles.exe writes into PreProcess\ at runtime AS THE LOCKED-DOWN OPERATOR,
|
|
# not admin. Without write access the GetDoDAFolder/merge step fails. Grant
|
|
# Users + Authenticated Users Full (object+container inherit). SIDs, not names,
|
|
# to stay locale-independent. Applied every run so it re-asserts after any
|
|
# lockdown pass that strips the ACE.
|
|
foreach ($sid in '*S-1-5-32-545','*S-1-5-11') { # BUILTIN\Users, NT AUTHORITY\Authenticated Users
|
|
& icacls $preProcess /grant "${sid}:(OI)(CI)F" /T /C 2>&1 | Out-Null
|
|
}
|
|
Write-Host "Granted Users + Authenticated Users Full on $preProcess"
|
|
|
|
if (Test-Path (Join-Path $installDir 'DovetailAnalysis.exe')) {
|
|
Write-Host "DovetailAnalysis.exe verified present"
|
|
exit 0
|
|
} else {
|
|
Write-Host "ERROR: DovetailAnalysis.exe not found after extract"
|
|
exit 1
|
|
}
|