software package profiles implemeted, job deletion optimized

This commit is contained in:
2026-09-26 13:07:23 +02:00
parent 87a5041162
commit 7d314057e4
54 changed files with 3492 additions and 342 deletions
+3 -1
View File
@@ -1,3 +1,5 @@
- [0.5.5.90](UPDATE-0.5.5.90.md) - modular analyzer profiles, community repository foundation and portable package import/export.
- [0.5.5.89](UPDATE-0.5.5.89.md) - recursively analyze supported SFX payloads and package selected embedded installers.
- [0.5.5.88](UPDATE-0.5.5.88.md) - keep title/filter rows sticky while preserving unified column resizing.
- [0.5.5.87](UPDATE-0.5.5.87.md) - unify interactive table behavior and restore column resizing with sticky two-row headers.
- [0.5.5.86](UPDATE-0.5.5.86.md) - fix status filtering so assets without a status remain visible in global software lists.
@@ -24,7 +26,7 @@
Release notes are stored outside the project root to keep the repository overview compact.
The current release is **0.5.5.88**.
The current release is **0.5.5.90**.
Older notes are concise English summaries migrated from the original release documents. Git history remains authoritative for exact implementation details.
+62
View File
@@ -0,0 +1,62 @@
# Update 0.5.5.89
## Setup Analyzer: SFX and embedded installers
- Detect supported 7-Zip and WinRAR/RAR SFX wrappers as outer containers.
- Statically extract supported SFX payloads without executing uploaded installers.
- ZIP-compatible SFX files are handled by Python directly.
- Container image now includes 7-Zip and `unar` / `lsar` for additional SFX formats.
- Recursively analyze embedded installer candidates up to a configurable depth.
- Rank embedded MSI and known EXE installer technologies while penalizing uninstallers and common prerequisite packages.
- Display the selected embedded installer and alternate candidates in Setup Analyzer.
- Preserve the complete selected payload tree in an internal deployment ZIP so CAB files and subdirectories remain available.
- Software-package install scripts expand the payload on the target and run the selected installer from its original relative directory.
- Add extraction safety limits for total expanded size, file count, path traversal, symbolic links and recursion depth.
## New environment settings
```text
SETUP_ANALYZER_MAX_EXTRACTED_MB=8192
SETUP_ANALYZER_MAX_EXTRACTED_FILES=20000
SETUP_ANALYZER_MAX_SFX_DEPTH=2
```
Embedded-installer selection remains heuristic and should be verified on a test asset before broad deployment.
## Software package cleanup
- Added a Delete button directly to every row of the software-package overview.
- Broken packages that show a storage error can be deleted without opening their detail page.
- If associated software jobs exist, the overview confirmation explicitly states that those jobs will be deleted too.
- Package summary handling now keeps the overview usable when either the manifest or package-size scan fails.
## Architecture detection fix
- Distinguishes installer-launcher PE architecture from the target software architecture.
- Known setup wrappers such as NSIS/Inno no longer classify a package as x86 merely because their launcher stub is PE32.
- Explicit x64/x86/ARM64 package filename hints are used as target-architecture evidence.
- The analyzer shows the launcher architecture and architecture source separately in technical details.
- Verified with `npp.8.9.8.Installer.x64.exe`: NSIS launcher x86, target package x64.
## Dispatcher ACL retry fix
- Upload retry no longer reapplies directory ACLs recursively to files already uploaded into the job directory.
- Windows job-directory ACLs are now applied only to the directory itself; uploaded files inherit the directory permissions normally.
- Package-file retry removes only the failed target file and leaves `run.ps1` and other package files untouched.
- A remote script preflight now logs existence, size, readability and Windows ACLs before execution.
- If the uploaded `run.ps1` is not readable, the dispatcher stops with a dedicated diagnostic error before trying to launch PowerShell.
## Total Commander SFX profile
- Recognize Total Commander's self-extracting ZIP installer through its embedded `INSTALL.INF`.
- Read product name, version, publisher, target architecture and running-process hint from embedded installer metadata.
- Use `/AH1` as the unattended default (automatic + hidden installation) and expose `/A1` as the visible automatic alternative.
- Keep the outer SFX executable as the deployment installer; its embedded CAB/INF files are installation data, not a replacement setup executable.
- Recognize architecture suffixes attached directly to version numbers such as `tcmd1156x64.exe`.
## PDF24 online bootstrapper profile
- Detect the small `pdf24-creator-installer.exe` bootstrapper through multiple vendor-specific static markers instead of reporting an unknown EXE at 25%.
- Distinguish the bootstrapper from the full PDF24 Creator Inno Setup package.
- Report `PDF24 Creator`, `geek software GmbH` and the bootstrapper's architecture-selecting behavior (`x86+x64+arm64`).
- Do not misreport the bootstrapper's own `1.0.0` file version as the PDF24 Creator version, because the bootstrapper downloads the current Creator release at deployment time.
- Surface `/SILENT` with medium command confidence and warn that this online bootstrapper is network-dependent and version-unpinned; prefer the offline EXE/MSI for reproducible managed deployment.
+58
View File
@@ -0,0 +1,58 @@
# Update 0.5.5.90
## Modular Setup Analyzer profiles
- Installer/vendor-specific Setup Analyzer knowledge is moved into declarative analyzer profiles.
- System, Community and Local profile sources are supported.
- `.amprofile` import/export validates schema, profile API and SHA-256 and contains no executable plugin code.
- Profiles can be enabled/disabled; imported Community/Local profiles can be deleted without modifying application source.
- Existing Total Commander, PDF24 and Greenshot-specific analyzer behavior is supplied as system profiles instead of Python special cases.
- Generic technology signatures for Inno Setup, NSIS, WiX Burn, InstallShield, Advanced Installer, Squirrel, 7-Zip SFX and WinRAR SFX are also supplied as profiles.
## Community repository foundation
- Optional HTTPS profile repository support via `ANALYZER_PROFILE_REPOSITORY_URL`.
- Repository index schema `assetmanager-analyzer-profile-repository-v1`.
- Admins explicitly load the repository catalog and select profiles to install.
- Optional repository SHA-256 is checked before a bundle is imported.
- Repository format/contribution documentation is included under `docs/analyzer-profiles/`.
## Portable software packages
- Stored software packages can now be exported as `.ampkg` bundles.
- Package overview can import `.ampkg` bundles and compatible Setup Analyzer ZIP exports.
- Imports validate ZIP paths, symlinks, required package files and available SHA-256 metadata.
- Import UI requires acknowledgement that software packages may contain executable PowerShell scripts.
- Imported analyzer profiles are included in AssetManager backup/restore.
## Automatic persistent directory initialization
- Docker Compose now mounts one persistent application root (`./data` -> `/assetmanager-data`) instead of requiring a separate host bind directory for every feature.
- The container entrypoint verifies and creates all required application subdirectories on every start, including analyzer profiles and software packages.
- Existing host data remains in the same `./data/...` layout; no data migration is required.
- The established `/scripts` container path remains available for existing job definitions.
- Uploaded images remain available under their existing `/static/uploads/...` URLs while being stored below the persistent data root.
## Import form and generic installer metadata fixes
- Software-package import checkboxes are rendered left-aligned, vertically stacked, and no longer inherit full-width input sizing.
- EXE analyzer metadata now uses a conservative dotted-version fallback from the installer filename when MSI/MSIX/PE metadata has no product version.
- Signed PE installers can use the Authenticode code-signing certificate organization/common name as a manufacturer fallback.
- The Authenticode publisher is only a fallback; explicit MSI/MSIX/PE manufacturer metadata still has higher priority.
- The generic metadata enrichment contains no VLC-specific Python logic; product-specific naming is supplied by the declarative VLC analyzer profile.
## Follow-up: VLC metadata, localized file picker and client job retention
- Added declarative VLC analyzer profile so NSIS VLC packages receive the product name `VLC media player` without product-specific Python code.
- Replaced browser-native file selector text in Setup Analyzer, analyzer-profile import and software-package import with translated AssetManager controls.
- Added configurable stale client job-directory cleanup with a default retention of 24 hours. Cleanup is limited to AssetManager job directories and runs before a new file-based job is dispatched to that client.
## Follow-up: reliable client job retention cleanup
- Stale client cleanup now uses the job-directory creation time on Windows instead of the mutable last-write timestamp.
- Current/active job directories are explicitly excluded from cleanup.
- Legacy numeric job directories and current `JobID-Attempt` directories are both recognized below the dedicated AssetManager job root.
- If deletion of an expired directory fails because of legacy/broken ACLs, AssetManager repairs permissions only inside that already-expired job directory and retries deletion.
- Cleanup still runs before new file-based jobs and now also runs periodically for online managed clients with job history, so stale files do not depend on a later deployment to be removed.
- Cleanup diagnostics now report found, eligible, removed, failed, young, active and ignored directory counts.