software packages and deploying

This commit is contained in:
2026-09-10 21:54:55 +02:00
parent 0fb18ae4f7
commit 4567df7ebb
73 changed files with 3088 additions and 6 deletions
+3 -1
View File
@@ -9,7 +9,7 @@ Create a dedicated directory and the persistent data directories:
```bash
mkdir -p /srv/docker/assetmanager
cd /srv/docker/assetmanager
mkdir -p data/config data/uploads data/logs data/backups data/scripts data/postgres
mkdir -p data/config data/uploads data/logs data/backups data/scripts data/software-packages data/postgres
```
Create a `.env` file. Use strong, unique values for all secrets:
@@ -89,6 +89,7 @@ services:
- ./data/logs:/app/data/logs
- ./data/backups:/data/backups
- ./data/scripts:/scripts
- ./data/software-packages:/app/data/software-packages
callback:
image: git.jusaro.de/roland/assetmanager:${ASSETMANAGER_VERSION:-0.5.5.68}
@@ -208,6 +209,7 @@ data/uploads/
data/logs/
data/backups/
data/scripts/
data/software-packages/
.env
```
+64
View File
@@ -0,0 +1,64 @@
# Setup Analyzer
The Setup Analyzer prepares Windows installation files for silent deployment without executing the uploaded installer on the AssetManager server.
## Supported package types
- MSI and MSP
- MSIX and AppX
- MSU
- Inno Setup
- NSIS
- WiX Burn
- InstallShield
- Advanced Installer
- Squirrel
- common 7-Zip and WinRAR SFX wrappers
- unknown EXE fallback
## Analysis output
- SHA256
- installer technology and confidence
- PE product/version/manufacturer/architecture metadata when available
- presence of Authenticode signature data for PE files
- detected installer marker strings
- detected switch-like strings
- recommended silent arguments and command
- success and reboot exit-code suggestions
- detection and uninstall suggestions
## Exports and AssetManager packages
The PowerShell export creates an `install.ps1` wrapper. The deployment-package export contains the original installer plus `install.ps1`, `uninstall.ps1`, `detect.ps1`, `package.json`, and `analysis.json`.
Version 0.5.5.77 can also create a persistent AssetManager software package directly from the analyzer result. Package files are stored in `data/software-packages/` and the package appears under **Software and Jobs → Software packages**. From there administrators can create install, uninstall, and reinstall jobs for one or more compatible Windows assets.
Software-package jobs transfer only the files required for the selected action through MeshCentral, run the generated PowerShell wrapper, and use the normal AssetManager callback/status/retry infrastructure.
## Installer process handling
Generated installation scripts no longer use `Start-Process -Wait` for the installer. They start the installer process, wait only for that specific PID with a configurable timeout, and then evaluate its exit code. This prevents a browser or another long-running child process launched by the installer from keeping the PowerShell script open indefinitely.
The optional **Suppress post-install browser launch** setting terminates only browser processes that were newly created inside the installer process tree. Existing browser sessions are not touched. The option is preselected for Greenshot detections because Greenshot installers can open a completion web page after setup.
## Security
The uploaded installer is stored in a temporary directory and is not executed. Access is restricted to administrators. Old temporary analyses are removed after the configured retention period.
Environment variables:
```text
SETUP_ANALYZER_TMP_DIR=/tmp/assetmanager-setup-analyzer
SETUP_ANALYZER_MAX_UPLOAD_MB=4096
SETUP_ANALYZER_RETENTION_HOURS=24
SOFTWARE_PACKAGE_DIR=/app/data/software-packages
```
## MSI metadata
Standard MSI silent-command generation works without additional system packages. Detailed MSI properties such as ProductCode and UpgradeCode are additionally read when the optional `msiinfo` utility is present in the container.
## Important
Installer technology detection and a suggested command do not guarantee vendor-specific compatibility. Test generated commands on a designated test asset before broad deployment.
+7 -1
View File
@@ -1,3 +1,9 @@
- [0.5.5.81](UPDATE-0.5.5.81.md) - fix generated PowerShell process-control syntax for software jobs.
- [0.5.5.80](UPDATE-0.5.5.80.md) - add configurable process control before install/uninstall and improve Inno application closing.
- [0.5.5.79](UPDATE-0.5.5.79.md) - fix Greenshot SYSTEM deployment and add software-package deletion.
- [0.5.5.78](UPDATE-0.5.5.78.md) - fix software-package job exit-code handling and action layout.
- [0.5.5.77](UPDATE-0.5.5.77.md) - add persistent software packages and install/uninstall/reinstall deployment jobs; fix installer wait behavior.
- [0.5.5.76](UPDATE-0.5.5.76.md) - add the static Setup Analyzer with silent-install command and deployment-script export.
- [0.5.5.75](UPDATE-0.5.5.75.md) - resize only the dragged table column while the total table width grows or shrinks by the same amount.
- [0.5.5.74](UPDATE-0.5.5.74.md) - keep column resize handles, filter cells and stored widths aligned after reordering Asset list columns.
- [0.5.5.73](UPDATE-0.5.5.73.md) - save table filters, sorting and column widths in the signed-in user account instead of only in browser storage.
@@ -11,7 +17,7 @@
Release notes are stored outside the project root to keep the repository overview compact.
The current release is **0.5.5.68**.
The current release is **0.5.5.81**.
Older notes are concise English summaries migrated from the original release documents. Git history remains authoritative for exact implementation details.
+23
View File
@@ -0,0 +1,23 @@
# AssetManager 0.5.5.76
## Added
- Added an administrator-only Setup Analyzer under **Software and Jobs → Software lists**.
- Added static installer detection for MSI, MSP, MSIX/AppX, MSU, Inno Setup, NSIS, WiX Burn, InstallShield, Advanced Installer, Squirrel, and common SFX wrappers.
- Added SHA256 calculation, PE metadata, architecture, Authenticode-presence indication, detection confidence, and detected switch strings.
- Added editable recommended silent arguments, success/reboot exit codes, execution context, and timeout.
- Added PowerShell installation-script export.
- Added deployment ZIP export containing the installer, `install.ps1`, `uninstall.ps1`, `detect.ps1`, `package.json`, and `analysis.json`.
- Added German and English interface translations for the analyzer.
## Security
- Uploaded installers are analyzed statically and are never executed on the AssetManager server.
- Analyzer access requires administrator permissions.
- Uploaded analysis files are stored below a temporary directory and removed automatically after the configured retention period.
## Compatibility
- Built directly on 0.5.5.75.
- Existing table filtering, column order, independent column resizing, and per-user stored table state remain unchanged.
- No database migration is required.
+23
View File
@@ -0,0 +1,23 @@
# AssetManager 0.5.5.77
## Added
- Added persistent AssetManager software packages created directly from Setup Analyzer results.
- Added a **Software packages** administration page under **Software and Jobs**.
- Added install, uninstall, and reinstall software jobs for stored packages.
- Added bulk asset selection for software-package jobs.
- Added MeshCentral transfer of installer/package files before package-job execution.
- Added package storage under `data/software-packages/` and included that storage in AssetManager backup and restore.
- Added an optional post-install browser suppression setting; Greenshot detections enable it by default.
## Fixed
- Generated installation PowerShell scripts no longer use `Start-Process -Wait`, which can wait for the complete child-process tree.
- Installer completion now waits for the setup PID only, with an explicit timeout, so browser child processes cannot keep the generated installation script open indefinitely.
- Added deployment timeout propagation to the MeshCentral dispatcher so longer package installations are not cut off by the default dispatcher timeout.
## Compatibility
- Built directly on 0.5.5.76, which itself was built on the verified 0.5.5.75 source tree.
- No database schema migration is required; the existing `software_packages` and `software_jobs` tables are used.
- Existing asset tables, filters, column order, column resizing, per-user table state, inventory jobs, and custom job definitions are unchanged.
+19
View File
@@ -0,0 +1,19 @@
# AssetManager 0.5.5.78
## Fixed
- Fixed software-package install, uninstall, and reinstall jobs when package scripts write text to standard output.
- Package script output is now captured into the AssetManager client log while the deployment helper returns exactly one integer exit code.
- Detection-script output is also captured without contaminating the returned Boolean detection result.
- Added defensive integer normalization for package-script exit codes before result validation.
- Fixed the software-package action selector layout so Install, Uninstall, and Reinstall stay compact and left-aligned instead of stretching beyond the viewport.
- Fixed generated registry detection so versioned display names such as `Greenshot 1.3.312` match the package name `Greenshot`.
- Generated uninstall scripts now prefer `QuietUninstallString`, log the selected registry entry and command, start the actual uninstaller process, and wait for its PID with a timeout.
- Reinstall jobs verify that the software is no longer detected before starting the installation step.
- Existing Setup-Analyzer software packages are refreshed automatically when their payload is prepared, so they do not need to be recreated for this fix.
## Compatibility
- Built directly on 0.5.5.77.
- Existing software packages remain compatible; they do not need to be recreated for this fix.
- No database schema migration is required.
+20
View File
@@ -0,0 +1,20 @@
# Update 0.5.5.79
## Software package deployment fixes
- Existing Setup Analyzer packages now refresh install, detect and uninstall runtime scripts before transfer.
- Greenshot Inno packages are normalized for SYSTEM deployment with `/ALLUSERS` and `/DIR="C:\Program Files\Greenshot"` unless an explicit scope or destination was configured.
- Inno installer execution logs the working directory, PID, exit code and selected setup-log diagnostics.
- Registry detection and uninstall support version-suffixed display names such as `Greenshot 1.3.312`.
## Software package administration
- Stored deployment packages can be deleted from the package detail page.
- If jobs reference the package, deleting those jobs requires a separate explicit checkbox.
- Package files under `data/software-packages/<id>` are removed with the package definition.
## Compatibility
- Built directly on 0.5.5.78.
- Existing Greenshot packages are normalized automatically and do not need to be recreated.
- No database schema migration is required.
+18
View File
@@ -0,0 +1,18 @@
# Update 0.5.5.80
## Software package process control
- Software packages can store executable names that must be closed before installation and uninstallation.
- AssetManager first requests a normal application close and waits for a configurable grace period.
- If enabled, remaining processes are terminated forcibly before deployment continues.
- Deployment logs report found processes, close requests, forced termination and remaining process errors.
- The process list, grace period and force-close behavior can be edited on the software-package detail page.
- Setup Analyzer suggests `Greenshot.exe` automatically for Greenshot packages.
- Existing Greenshot packages are normalized automatically and receive the process-control preset when they are loaded or used.
- Inno Setup packages with process control also receive `/CLOSEAPPLICATIONS` and `/FORCECLOSEAPPLICATIONS` when appropriate.
## Compatibility
- Based on 0.5.5.79.
- No database migration is required; process-control settings are stored in the package manifest.
- Existing software packages remain compatible.
+14
View File
@@ -0,0 +1,14 @@
# Update 0.5.5.81
## Fixed
- Correct generated PowerShell syntax in software-package process control.
- Avoid invalid `$Phase:` variable references in generated install and uninstall scripts.
- Process-control logging now builds the phase label using string concatenation.
- Existing package runtime scripts are regenerated automatically before the next software job.
## Effect
Version 0.5.5.80 could generate an `uninstall.ps1` that failed during PowerShell parsing before any process-control or uninstall command was executed. Version 0.5.5.81 fixes this generator error.
Existing software packages do not need to be recreated.