# Update 0.5.5.89 ## Setup Analyzer: SFX and embedded installers - Detect supported 7-Zip and WinRAR/RAR SFX wrappers as outer containers. - Statically extract supported SFX payloads without executing uploaded installers. - ZIP-compatible SFX files are handled by Python directly. - Container image now includes 7-Zip and `unar` / `lsar` for additional SFX formats. - Recursively analyze embedded installer candidates up to a configurable depth. - Rank embedded MSI and known EXE installer technologies while penalizing uninstallers and common prerequisite packages. - Display the selected embedded installer and alternate candidates in Setup Analyzer. - Preserve the complete selected payload tree in an internal deployment ZIP so CAB files and subdirectories remain available. - Software-package install scripts expand the payload on the target and run the selected installer from its original relative directory. - Add extraction safety limits for total expanded size, file count, path traversal, symbolic links and recursion depth. ## New environment settings ```text SETUP_ANALYZER_MAX_EXTRACTED_MB=8192 SETUP_ANALYZER_MAX_EXTRACTED_FILES=20000 SETUP_ANALYZER_MAX_SFX_DEPTH=2 ``` Embedded-installer selection remains heuristic and should be verified on a test asset before broad deployment. ## Software package cleanup - Added a Delete button directly to every row of the software-package overview. - Broken packages that show a storage error can be deleted without opening their detail page. - If associated software jobs exist, the overview confirmation explicitly states that those jobs will be deleted too. - Package summary handling now keeps the overview usable when either the manifest or package-size scan fails. ## Architecture detection fix - Distinguishes installer-launcher PE architecture from the target software architecture. - Known setup wrappers such as NSIS/Inno no longer classify a package as x86 merely because their launcher stub is PE32. - Explicit x64/x86/ARM64 package filename hints are used as target-architecture evidence. - The analyzer shows the launcher architecture and architecture source separately in technical details. - Verified with `npp.8.9.8.Installer.x64.exe`: NSIS launcher x86, target package x64. ## Dispatcher ACL retry fix - Upload retry no longer reapplies directory ACLs recursively to files already uploaded into the job directory. - Windows job-directory ACLs are now applied only to the directory itself; uploaded files inherit the directory permissions normally. - Package-file retry removes only the failed target file and leaves `run.ps1` and other package files untouched. - A remote script preflight now logs existence, size, readability and Windows ACLs before execution. - If the uploaded `run.ps1` is not readable, the dispatcher stops with a dedicated diagnostic error before trying to launch PowerShell. ## Total Commander SFX profile - Recognize Total Commander's self-extracting ZIP installer through its embedded `INSTALL.INF`. - Read product name, version, publisher, target architecture and running-process hint from embedded installer metadata. - Use `/AH1` as the unattended default (automatic + hidden installation) and expose `/A1` as the visible automatic alternative. - Keep the outer SFX executable as the deployment installer; its embedded CAB/INF files are installation data, not a replacement setup executable. - Recognize architecture suffixes attached directly to version numbers such as `tcmd1156x64.exe`. ## PDF24 online bootstrapper profile - Detect the small `pdf24-creator-installer.exe` bootstrapper through multiple vendor-specific static markers instead of reporting an unknown EXE at 25%. - Distinguish the bootstrapper from the full PDF24 Creator Inno Setup package. - Report `PDF24 Creator`, `geek software GmbH` and the bootstrapper's architecture-selecting behavior (`x86+x64+arm64`). - Do not misreport the bootstrapper's own `1.0.0` file version as the PDF24 Creator version, because the bootstrapper downloads the current Creator release at deployment time. - Surface `/SILENT` with medium command confidence and warn that this online bootstrapper is network-dependent and version-unpinned; prefer the offline EXE/MSI for reproducible managed deployment.