.. Reminder for header structure: Parts (H1) : #################### with overline Chapters (H2) : ******************** with overline Sections (H3) : ==================== Subsections (H4) : -------------------- Subsubsections (H5) : ^^^^^^^^^^^^^^^^^^^^ Paragraphs (H6) : """"""""""""""""""""" .. meta:: :description: Creating WAPT packages :keywords: working, WAPT, personalizing, creating packages, documentation .. |vscode| image:: wapt-resources/icon_visual-studio-text-editor.png :alt: Visual Studio text editor .. |vscodium| image:: wapt-resources/icon_vscodium-text-editor.png :alt: VSCodium text editor .. |vim| image:: wapt-resources/icon_vim-text-editor.png :alt: Vim text editor .. |pyscripter| image:: wapt-resources/icon_pyscripter-text-editor.png :alt: Pyscripter text editor .. |pycharm| image:: wapt-resources/icon_pycharm-text-editor.png :alt: Pycharm text editor .. |notepad++| image:: wapt-resources/icon_notepadpluplus-text-editor.png :alt: Notepad ++ text editor .. |nano| image:: wapt-resources/icon_nano-text-editor.png :alt: Nano text editor .. _creating_WAPT_packages: #################################### Getting start creating WAPT packages #################################### ***************************************************** Setting up your WAPT development and test environment ***************************************************** Prerequisites ============= .. attention:: * It is **required** to be a :term:`Local Administrator` of the host to use WAPT's integrated environment for developing WAPT packages. * We advise you to create/ edit packages in a fully controlled environment that is safe and *disposable*. * The usage of a disposable virtual host (like Virtualbox) is recommended. * Import the *tis-waptdev* package in your local repository and install it on your development computer. Recommendations regarding the test environment ============================================== The recommended method to correctly test your WAPT packages is to use representative sample of hosts in your inventory. So the more heterogeneous your installed base of hosts, the larger your sample should be. This method consists of testing the installation of the package on as many platforms and configurations as possible, so to improve its reliability, before the WAPT package is transferred to production repositories. Testing method ============== Operating systems and architectures ----------------------------------- * Windows XP; * Windows 7; * Windows 10; * Windows Server 2008 R2; * Windows Server 2012 and R2; * x86; * x64; * Physical and virtual hosts; * Laptops. When possible, RC and Beta version of Operating Systems should be tested. State of Windows Updates ------------------------ * **Microsoft Windows host without any Windows update installed**: the objective is to detect Windows updates that are required for the software to work properly and to adapt the WAPT package accordingly; * **Microsoft Windows host with all the latest Windows updates**: the objective is to detect Windows updates that break the package and to adapt the WAPT package accordingly; State of software installations ------------------------------- * **Hosts with many installed packages**: the objective is to detect a possible dependency with an existing application; * **Hosts with many installed packages**: the objective is to detect a possible conflict with an existing application; * **Install older versions of the software**: it is possible that the software installer does not support uninstalling a previous version of the software, in this case, the WAPT package will have to remove older versions of the software before installing the new version; .. _create_package_from_console: ************************************************************* Principles of creating package template from the WAPT Console ************************************************************* .. attention:: To create WAPT packages directly from the WAPT Console, it is necessary to have installed the WAPT development environment **tis-pyscripter3**. It is NOT recommended to use **tis-pyscripter4**. We recommand you to download the **waptdev** package instead and install it on your computer on which you will create WAPT packages. If you do not remember how to download a package from the Tranquil IT store, please see :ref:`how to download package in your private repository `. If you do not remember how to install a package, please see :ref:`how to install a package on a host `. Creating a package template from the WAPT Console ================================================= In that example, we use the 7-zip MSI setup downloaded from the 7-zip official website. * `Download 7-zip MSI x64 `_. * Create a WAPT package Template from the installer. In the WAPT Console, click on :menuselection:`Tools --> Make package template from setup file`: .. figure:: wapt-resources/wapt_console_make-package-template_menu-option.png :align: center :alt: Menu option for creating a WAPT package template in the WAPT Console Menu option for creating a WAPT package template in the WAPT Console Select the downloaded MSI setup file and fill in the required fields. Verify that the package name does not contains any version number. .. figure:: wapt-resources/wapt_console_package-wizard1_dialog-box.png :align: center :alt: Dialog box requesting information when creating the WAPT package in the WAPT Console Dialog box requesting information when creating the WAPT package in the WAPT Console * Two solutions are available: * Click on :guilabel:`Make and edit ...` (recommended) to verify the WAPT package and customize it to your Organization's specific needs. * Click on :guilabel:`Build and upload` to directly build and upload the package into your private repository. .. attention:: The button :guilabel:`Build and upload` directly uploads the package into the private repository without testing. This method works relatively well with MSI installers because their installation is more standardized. However, the first method that consists of first testing locally the package before uploading is the recommended method. .. note:: :ref:`An old command line method is also available `. Customizing the WAPT package before uploading it to the repository ================================================================== Before uploading a package to your WAPT repository, you may choose to customize its behavior to your Organization's needs by editing it with :program:`PyScripter`. When creating the package template, click on :guilabel:`Make and edit ...`. .. figure:: wapt-resources/wapt_console_package-wizard_make-and-edit-button_dialog-box.png :align: center :alt: Dialog box highlighting the "Make and edit ..." button when creating the WAPT package in the WAPT Console Dialog box highlighting the "Make and edit ..." button when creating the WAPT package in the WAPT Console .. figure:: wapt-resources/wapt_console_package-wizard-downloaded_ok-message-window.png :align: center :alt: Message window showing in the WAPT Console that the WAPT package has been downloaded into the WAPT repository Message window showing in the WAPT Console that the WAPT package has been downloaded into the WAPT repository The :program:`PyScripter` IDE launches automatically to allow you to edit files in the WAPT package. .. figure:: wapt-resources/windows_pyscripter_package-template-opened_container-window.png :align: center :alt: PyScripter - Customizing a WAPT package within PyScripter PyScripter - Customizing a WAPT package within PyScripter Presentation of PyScripter ========================== PyScripter project explorer --------------------------- .. figure:: wapt-resources/windows_pyscripter_project_explorer_browser-windows.png :align: center :alt: PyScripter - Navigating a project within the PyScrypter file explorer PyScripter - Navigating a project within the PyScrypter file explorer The PyScripter project explorer lists the different files that you might need, notably the :file:`control` file and the :file:`setup.py` file. Run Configurations ------------------ .. figure:: wapt-resources/windows_pyscripter_run-configurations_menu_list.png :align: center :alt: PyScripter - Navigating the Run configurations of a project in PyScripter PyScripter - Navigating the Run configurations of a project in PyScripter The :command:`Run` option in the project explorer of :program:`PyScripter` will allow you to launch actions on the packages that you are editing. Editor panel ------------ .. figure:: wapt-resources/windows_pyscripter_project-explorer_browser-windows.png :align: center :alt: PyScripter - Editing a WAPT package with PyScripter PyScripter - Editing a WAPT package with PyScripter The edition panel in :program:`PyScripter` allows to edit the :file:`setup.py` file and the :file:`control` file. Python console -------------- .. figure:: wapt-resources/windows_pyscripter-project-zone-python-running_container-window.png :align: center :alt: PyScripter - Running the Python console from within Pyscripter PyScripter - Running the Python console from within Pyscripter This is the Python console visible in :program:`PyScripter`, it will allow you to display the python output when you execute :command:`Run` commands. You can also use it to test/ debug portions of your script :file:`setup.py`. To learn more about the composition of a WAPT package, visit the documentation on the :ref:`structure of a WAPT package `. Testing locally the installation of the WAPT package ---------------------------------------------------- You can then test the launch of an installation on your development station. .. image:: wapt-resources/windows_pyscripter_run-install_menu-item.png :align: center :alt: PyScripter - Running an install command from the PyScripter console The PyScripter console allows you to check whether the installation went well. Testing locally the uninstallation of the WAPT package ------------------------------------------------------ You can then test the uninstall script on your development station. .. image:: wapt-resources/windows_pyscripter_run-remove_menu-item.png :align: center :alt: PyScripter - Running a remove command from the PyScripter console The PyScripter console allows you to check whether the uninstallation went well. Exploring Package Files with the WAPT Console ============================================= To explore all the files of a WAPT package using the WAPT Console, you must enable the :guilabel:`Show Developer Features` option. To do this: * Go to the :kbd:`View` tab in the WAPT Console. * Select :guilabel:`Display Preferences` and activate the :guilabel:`Show Developer Features checkbox`. How to explore package files ? Navigate to :command:`WAPT Packages` section, select your package and do a right-click on :kbd:`Edit package` Once enabled, you can access the file explorer for the package. .. figure:: wapt-resources/WAPT-Console_techview.png :align: center :alt: WAPT Console techview WAPT Console techview ********************************* Creating your first WAPT Packages ********************************* Packaging .msi packages (example) ================================= For this example we will take :program:`tightvnc`. You can download it `here `_. Now, you can then generate your package template, please refer to the :ref:`documentation for creating packages from the WAPT Console `. Edit the :file:`control` file (:code:`architecture`, :code:`impacted_process`, :code:`target_os`, :code:`description`, :code:`maintainer` ...). For more information, visit the :ref:`documentation on the control file structure `. Your :program:`PyScripter` opens, go to your :file:`setup.py`: .. code-block:: python # -*- coding: utf-8 -*- from setuphelpers import * uninstallkey = [] def install(): print('installing tis-tightvnc') install_msi_if_needed('tightvnc-2.8.5-setup-64bit.msi') * The function will test whether a version of the software is already installed on the host using the *uninstall key*. * If the *uninstall key* is already present, the new version of the software will be installed only if the installed version is older. * After the installation, the function will finally test that the *uninstall key* is present and its version, to ascertain that all went well. .. list-table:: List of arguments available with *install_msi_if_needed* :header-rows: 1 :widths: 50, 50 :align: center * - Options (Default Option) - Description * - :code:`min_version` (default ``None``) - Defines the minimal version above which the software will update. * - :code:`killbefore` (default ``None``) - Lists the programs to kill before installing the package. * - :code:`accept_returncodes` (default ``[0,3010]``) - Defines the accepted codes other than 0 and 3010 returned by the function. * - :code:`timeout` (default ``300``) - Defines the maximum installation wait time (in seconds). * - :code:`properties` (default ``None``) - Defines the additional properties to pass as arguments to MSI setup file. * - :code:`get_version` (default ``None``) - Defines the value passed as parameter to control the version number instead of the value returned by the *installed_softwares* function. Ex * - :code:`remove_old_version` (default ``False``) - Automatically removes an older version of a software whose *uninstall key* is identical. * - :code:`force` (default ``False``) - Forces the installation of the software even though the same *uninstall key* has been found. The :command:`wapt-get install_msi_if_needed` method searches for an *uninstall key* in the MSI file properties, it is not necessary to fill it manually in the :file:`setup.py` file. You also do not have to fill in :code:`killbefore` if the value specified in the :code:`impacted_process` field of the :file:`control` file is correct. .. note:: The :file:`setup.py` could have looked like this, but the method is less elegant because it does less checking. .. code-block:: python # -*- coding: utf-8 -*- from setuphelpers import * uninstallkey = ["{8B9896FC-B4F2-44CD-8B6E-78A0B1851B59}"] def install(): print('installing tis-tightvnc') run('msiexec /norestart /q /i "tightvnc-2.8.5-setup-64bit.msi"') Run the installation and see what happens when the software is already installed. .. code-block:: bash wapt-get -ldebug install C:\waptdev\tis-tightvnc-wapt Installing WAPT file C:\waptdev\tis-tightvnc-wapt MSI tightvnc-2.8.5-gpl-setup-64bit.msi already installed. Skipping msiexec Results: === install packages === C:\waptdev\tis-tightvnc-wapt | tis-tightvnc (2.8.5.0-1) Passing additional arguments ---------------------------- To pass additional arguments, store them in a *dict*. .. code-block:: python # -*- coding: utf-8 -*- from setuphelpers import * uninstallkey = [] properties = { 'SERVER_REGISTER_AS_SERVICE': 0, 'SERVER_ADD_FIREWALL_EXCEPTION': 0, 'ADDLOCAL': 'Server,Viewer' } def install(): print(u'Installation en cours de TightVNC') install_msi_if_needed('tightvnc-2.8.5-setup-64bit.msi', properties = properties ) .. note:: The :file:`setup.py` could have looked like this, but the method is less elegant because it does less checking. .. code-block:: python # -*- coding: utf-8 -*- from setuphelpers import * uninstallkey = ["{8B9896FC-B4F2-44CD-8B6E-78A0B1851B59}"] def install(): print('installing tis-tightvnc') run('msiexec /norestart /q /i "tightvnc-2.8.5-setup-64bit.msi" SERVER_REGISTER_AS_SERVICE=0 SERVER_ADD_FIREWALL_EXCEPTION=0') Video demonstration ------------------- .. youtube:: Z6wr6emPGCU .. _simple_exe_packaging: Packaging .exe packages (example) ================================= * Download the :mimetype:`.exe` installer from a reliable source. Download the installer in exe format Firefox ESR x64 on ``_. * Look up documentation relating to silent flags: * On the `Official Mozilla website `_. * Other methods for finding information on silent flags: * `WPKG packages repository `_; * `Chocolatey packages repository `_; * Search on the Internet with the search terms: *Firefox silent install*. * Then generate your package template, please refer to the :ref:`documentation for creating packages from the WAPT Console `. :program:`PyScripter` loads up and opens the :mimetype:`.exe` package project. .. figure:: wapt-resources/windows_pyscripter_firefox_esr_browser-window.png :align: center :alt: PyScripter - Opening the FirefoxESR WAPT package PyScripter - Opening the FirefoxESR WAPT package * Edit the :file:`control` file (:code:`architecture`, :code:`impacted_process`, :code:`target_os`, :code:`description`, :code:`maintainer` ...). For more information, visit the :ref:`documentation on the control file structure `. * Check the :file:`control` file content. Mozilla Firefox-ESR does not comply to industry standards and returns an erroneous version number (it appears to be the installer packaging software version number). * Original :file:`control` file. .. literalinclude:: wapt-resources/package-exe-control_origin.txt :emphasize-lines: 2 * Modified :file:`control` file. .. literalinclude:: wapt-resources/package-exe-control_modified.txt :emphasize-lines: 2,6,7,8 A sub-version *-1* has been appended to the software version number; it is the packaging version of the WAPT package. It allows the Package Developer to release several WAPT package versions of the same software, very useful for very rapid and iterative development. Using *install_exe_if_needed* The function is slightly the same as that used with :mimetype:`.msi` installers, with some differences: * The function requires to pass the silent flag as an argument. * The function requires to pass the *uninstall key* as an argument. .. code-block:: python # -*- coding: utf-8 -*- from setuphelpers import * uninstallkey = [] def install(): print('installing tis-firefox-esr') install_exe_if_needed("Firefox Setup 45.5.0esr.exe",silentflags="-ms",key='',min_version="4.42.0.0") .. list-table:: List of arguments available with *install_exe_if_needed* :header-rows: 1 :widths: 50, 50 :align: center * - Options (Default Option) - Description * - :code:`silentflags` (default ``None``) - Defines the silent parameters to pass as arguments to the installer. * - :code:`key` (default ``None``) - Defines the software *uninstall key*. * - :code:`min_version` (default ``None``) - Defines the minimal version above which the software will update. * - :code:`killbefore` (default ``None``) - Lists the programs to kill before installing the package. * - :code:`accept_returncodes` (default ``[0,3010]``) - Defines the accepted codes other than 0 and 3010 returned by the function. * - :code:`timeout` (default ``300``) - Defines the maximum installation wait time (in seconds). * - :code:`get_version` (default ``None``) - Defines the value passed as parameter to control the version number instead of the value returned by the *installed_softwares* function. Example ``_ * - :code:`remove_old_version` (default ``False``) - Automatically removes an older version of a software whose *uninstall key* is identical. * - :code:`force` (default ``False``) - Forces the installation of the software even though the same *uninstall key* has been found. The package will then have this behavior: * Firefox will install only if Firefox is not yet installed or if the installed version of Firefox is less than 45.5.0, unless the :code:`--force` option is passed as argument when installing the package. * On installing, the running :program:`firefox.exe` processes will be killed (with the value indicated in :code:`impacted_process` of the :file:`control` file). * The function will add by itself the *uninstall key*, so leave the *uninstall key* argument empty. * When finishing the installation of the package, the function will check that the *uninstall key* is present on the host and that the version of Firefox is greater than 45.5.0; if this not the case, the package will be flagged as **ERROR**. Finding the uninstallation key ------------------------------ Unlike :mimetype:`.msi` files, the key to uninstall an :mimetype:`.exe` is not in the file properties. So you need to install the software first to know the uninstall key. Therefore you **MUST** start once the installation from :program:`PyScripter` with the :guilabel:`run configuration` and then :guilabel:`install`. .. image:: wapt-resources/windows_pyscripter_run-install_menu-item.png :align: center :alt: PyScripter - Running an install command from the PyScripter console Once the software is installed, go to the WAPT Console, then find your development host. In the :guilabel:`Software inventory` tab find the software title and copy the value indicated in the uninstallkey column. .. figure:: wapt-resources/wapt_console_uninstallkey-select_screen-item.png :align: center :alt: Retrieving an uninstallkey from the WAPT Console Retrieving an uninstallkey from the WAPT Console You **MUST** also check the value of the version with the value indicated in :code:`min_version` in your :file:`setup.py`. Modify your :file:`setup.py` with the new parameters: .. code-block:: python # -*- coding: utf-8 -*- from setuphelpers import * uninstallkey = [] def install(): print('installing tis-firefox-esr') install_exe_if_needed("Firefox Setup 45.5.0esr.exe",silentflags="-ms",key='Mozilla Firefox 45.5.0 ESR (x64 fr)',min_version="45.5.0") To test that your key works correctly, you **MUST** run an installation again in :program:`PyScripter`. .. image:: wapt-resources/windows_pyscripter_run-install_menu-item.png :align: center :alt: PyScripter - Running an install command from the PyScripter console WAPT should not attempt to install the software because it is already present, the following message should display: .. code-block:: python :emphasize-lines: 6 >>> *** Remote Interpreter Reinitialized *** Command Line : install "c:\waptdev\tis-firefox-esr_x64_PROD_fr-wapt\WAPT\.." Using config file: C:\Program Files (x86)\wapt\wapt-get.ini Installing WAPT files c:\waptdev\tis-firefox-esr_x64_PROD_fr-wapt Exe setup Firefox_Setup_78.7.1esr.exe already installed. Skipping Results: === install packages === c:\waptdev\tis-firefox-esr_x64_PROD_fr-wapt | tis-firefox-esr (78.7.1-102) Now you can now test the uninstallation: .. image:: wapt-resources/windows_pyscripter_run-remove_menu-item.png :align: center :alt: PyScripter - Running a remove command from the PyScripter console You can now build and upload your package, please refer to the :ref:`documentation for build and upload packages from the WAPT Console `. .. note:: If you leave the uninstallkey blank, uninstalling your package will not work. Special case of a non-silent uninstaller ---------------------------------------- In some particular cases, a package using :command:`install_exe_if_needed` fills in the *uninstall key*, but the *uninstall key* points to a non silent uninstaller. We have to circumvent that problem by using a function that will remove the *uninstall key* at the end of the installation. .. code-block:: python :emphasize-lines: 13 # -*- coding: utf-8 -*- from setuphelpers import * uninstallkey = [] def install(): install_exe_if_needed("setup.exe", silentflags="/s", key='{D9E87643-0005-447E-9111-78697A9C1595}', min_version="14.0") uninstallkey.remove('{D9E87643-0005-447E-9111-78697A9C1595') def uninstall(): run(r'"C:\Program Files\Kutl\uninstall.exe" /supersilent') .. hint:: The uninstall feature can also be used to run code in addition to uninstalling software, ex: delete folder, delete shortcut ... Video demonstration ------------------- .. youtube:: z_EN2CBCTcY .. _packaging_empty_packages: Packaging empty packages ======================== .. _build_upload_from_console: Building the package and sending it to the WAPT Server ====================================================== * Once the package is ready, build it and send it to the WAPT Server. .. image:: wapt-resources/wapt_console_build-upload_menu-item.png :align: center :alt: Menu option *build-upload* in the WAPT Console * Select the package in the :file:`c:\\waptdev` folder. .. figure:: wapt-resources/wapt_console-build-upload-select-folder_browser-window.png :align: center :alt: Browser window for selecting the WAPT package to import into the private repository Browser window for selecting the WAPT package to import into the private repository * Confirm the selected package. .. figure:: wapt-resources/wapt_console_build-upload-confirm_dialog-box.png :align: center :alt: WAPT Console dialog box for confirming the importation of a WAPT package into the private repository WAPT Console dialog box for confirming the importation of a WAPT package into the private repository You have just uploaded your first wapt package. .. note:: :ref:`A command line method is available here `. .. warning:: Once your package has uploaded, refresh the package list using the :guilabel:`Refresh packages list` button or by pressing :kbd:`F5` on your keyboard. .. _returncodes: Working with non standard return codes -------------------------------------- Return codes are used to feed back information on whether a software has installed correctly. In Windows, the standard successful return code is [0]. If you know that your WAPT packages installs correctly, yet you still get a return code other than ``[0]``, then you can explicitly tell WAPT to ignore the error code by using the parameter :code:`accept_returncodes`. You can find out how to use the :code:`accept_returncodes` parameter by exploring this package code. .. code-block:: python :emphasize-lines: 30 # -*- coding: utf-8 -*- from setuphelpers import * import re uninstallkey = [] def is_kb_installed(hotfixid): installed_update = installed_windows_updates() if [kb for kb in installed_update if kb['HotFixID' ].upper() == hotfixid.upper()]: return True return False def waiting_for_reboot(): # Query WUAU from the registry if reg_key_exists(HKEY_LOCAL_MACHINE,r"SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired") or \ reg_key_exists(HKEY_LOCAL_MACHINE,r"SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\RebootPending") or \ reg_key_exists(HKEY_LOCAL_MACHINE,r'SOFTWARE\Microsoft\Updates\UpdateExeVolatile'): return True return False def install(): kb_files = [ 'windows10.0-kb4522355-x64_af588d16a8fbb572b70c3b3bb34edee42d6a460b.msu', ] with EnsureWUAUServRunning(): for kb_file in kb_files: kb_guess = re.findall(r'^.*-(KB.*)-',kb_file) if not kb_guess or not is_kb_installed(kb_guess[0]): print('Installing {}'.format(kb_file)) run('wusa.exe "{}" /quiet /norestart'.format(kb_file),accept_returncodes=[0,3010,2359302,-2145124329],timeout=3600) else: print('{} already installed'.format(kb_file)) if waiting_for_reboot(): print('A reboot is needed!') .. hint:: The full list of Windows Installer Error Messages can be found by visiting `this page `_. ######################### How to code WAPT packages ######################### .. _common_setuphelper_functions: ****************************************************** Simple examples of commonly used setuphelper functions ****************************************************** Presentation of several functions implemented in :term:`Setuphelpers` and frequently used to develop WAPT packages. Testing and manipulating folders and files ========================================== Creating a path recursively --------------------------- Command :command:`makepath` makes the path variable for :file:`C:\\Program Files (x86)\\Mozilla\\Firefox`. .. code-block:: python makepath(programfiles,'Mozilla','Firefox') Creating and destroying directories ----------------------------------- Command :command:`mkdirs` creates the directory :file:`C:\\test`. .. code-block:: python mkdirs('C:\\test') Command :command:`remove_tree` destroys the directory :file:`C:\\tmp\\target`. .. code-block:: python remove_tree(r'C:\tmp\target') Checking if a path is a file or a folder ---------------------------------------- Command :command:`isdir` checks whether :file:`C:\\Program Files (x86)\\software` is a directory. .. code-block:: python isdir(makepath(programfiles32,'software')): print('The directory exists') Command :command:`isfile` checks whether :file:`C:\\Program Files (x86)\\software\\file` is a file. .. code-block:: python isfile(makepath(programfiles32,'software','file')): print('file exist') Checking whether a directory is empty ------------------------------------- Command :command:`dir_is_empty` checks that directory :file:`C:\\Program Files (x86)\\software` is empty. .. code-block:: python dir_is_empty(makepath(programfiles32,'software')): print('dir is empty') Copying a file -------------- Command :command:`filecopyto` copies :file:`file.txt` into the :file:`C:\\Program Files (x86)\\software` directory. .. code-block:: python filecopyto('file.txt',makepath(programfiles32,'software')) Copying a directory ------------------- Command :command:`copytree2` copies the :file:`sources` folder into the :file:`C:\\projet` directory. .. code-block:: python copytree2('sources','C:\\projet') Manipulating registry keys ========================== Checking the existence of a registry key ---------------------------------------- Command :command:`registry_readstring` checks if registry key *{8A69D345-D564-463c-AFF1-A69D9E530F96}* exists in registry path :file:`SOFTWARE\\Google\\Update\\Clients` of *HKEY_LOCAL_MACHINE*. .. code-block:: python if registry_readstring(HKEY_LOCAL_MACHINE, "SOFTWARE\\Google\\Update\\Clients\\{8A69D345-D564-463c-AFF1-A69D9E530F96}", 'pv'): print('key exist') Showing the value of a registry key ----------------------------------- Command :command:`registry_readstring` reads the value *{8A69D345-D564-463c-AFF1-A69D9E530F96}* stored in the registry path :file:`SOFTWARE\\Google\\Update\\Clients` of *HKEY_LOCAL_MACHINE*. .. code-block:: python print(registry_readstring(HKEY_LOCAL_MACHINE, r'SOFTWARE\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}', 'pv')) Modifying the value of a registry key ------------------------------------- Command :command:`registry_setstring` modifies the value of the registry key *TOUVersion* stored in the registry path :file:`SOFTWARE\\Microsoft\\Windows Live` of *HKEY_CURRENT_USER*. .. code-block:: python registry_setstring(HKEY_CURRENT_USER, "SOFTWARE\\Microsoft\\Windows Live\\Common",'TOUVersion','16.0.0.0', type=REG_SZ) Creating and destroying shortcuts ================================= With WAPT setuphelper it is possible to create different types of shortcuts. Creating a desktop shortcut for all users ----------------------------------------- Command :command:`create_desktop_shortcut` creates the shortcut *WAPT Console Management* into :file:`C:\\Users\\Public` directory pointing to :file:`C:\\Program Files (x86)\\wapt\\waptconsole.exe`; the shortcut is available for all users. .. code-block:: python create_desktop_shortcut(r'WAPT Console Management',target=r'C:\Program Files (x86)\wapt\waptconsole.exe') Removing a desktop shortcut for all users ----------------------------------------- Command :command:`remove_desktop_shortcut` deletes the *WAPT Console Management* shortcut from the folder :file:`C:\\Users\\Public`; the shortcut is deleted for all users. .. code-block:: python remove_desktop_shortcut('WAPT Console Management') Firefox places a shortcut on the all users desktop, we are going to delete it. We will use the :command:`remove_desktop_shortcut` function: * Modify your :file:`setup.py` and use the function like this. .. code-block:: python # -*- coding: utf-8 -*- from *SetupHelpers* import * uninstallkey = [] def install(): install_exe_if_needed("Firefox Setup 45.5.0esr.exe",silentflags="-ms",key='Mozilla Firefox 45.5.0 ESR (x64 fr)',min_version="45.5.0") remove_desktop_shortcut('Firefox') * If you restart the installation from :program:`PyScripter`, you will notice that the "all users" desktop shortcut has disappeared. Creating a menu shortcut for an application ------------------------------------------- Command :command:`create_programs_menu_shortcut` creates the shortcut *WAPT Console Management* into start menu pointing to :file:`C:\\Program Files (x86)\\wapt\\waptconsole.exe`; the shortcut is available for all users. .. code-block:: python create_programs_menu_shortcut(r'WAPT Console Management',target=r'C:\Program Files (x86)\wapt\waptconsole.exe') Removing a menu shortcut for an application ------------------------------------------- Command :command:`remove_programs_menu_shortcut` deletes the *WAPT Console Management* shortcut from start menu. .. code-block:: python remove_programs_menu_shortcut('WAPT Console Management') Creating a desktop shortcut for a logged in user ------------------------------------------------ .. hint:: These functions are used in session_setup context. Command :command:`create_user_desktop_shortcut` creates the shortcut *WAPT Console Management* on user desktop pointing to :file:`C:\\Program Files (x86)\\wapt\\waptconsole.exe`. .. code-block:: python create_user_desktop_shortcut(r'WAPT Console Management',target=r'C:\Program Files (x86)\wapt\waptconsole.exe') Removing a desktop shortcut for a logged in user ------------------------------------------------ Command :command:`remove_user_desktop_shortcut` deletes the *WAPT Console Management* shortcut from the logged in user's desktop. .. code-block:: python remove_user_desktop_shortcut('WAPT Console Management') Creating a menu shortcut to an application for a specific user -------------------------------------------------------------- .. hint:: These functions are used in session_setup context. Command :command:`create_user_programs_menu_shortcut` creates the shortcut *WAPT Console Management* on user start menu pointing to :file:`C:\\Program Files (x86)\\wapt\\waptconsole.exe`. .. code-block:: python create_user_programs_menu_shortcut(r'WAPT Console Management',target=r'C:\Program Files (x86)\wapt\waptconsole.exe') Removing a menu shortcut to an application for a specific user -------------------------------------------------------------- Command :command:`remove_user_programs_menu_shortcut` deletes the *WAPT Console Management* shortcut from the logged in user's start menu. .. code-block:: python remove_user_programs_menu_shortcut('WAPT Console Management') Manipulating ini files ====================== Reading a value in a section of a ini file ------------------------------------------ Command :command:`inifile_readstring` will read a value from a key and a section of a ini file. .. code-block:: python inifile_writestring("file.ini","global","key") Writing a value in a section of a ini file ------------------------------------------ Command :command:`inifile_writestring` will modify a value from a key and a section of a ini file. .. code-block:: python inifile_writestring("file.ini","global","key","value") Deleting a key in a section of a ini file ----------------------------------------- Command :command:`inifile_deleteoption` will delete a key in a given section of a ini file. .. code-block:: python inifile_deleteoption("file.ini","global","key") Deleting an entire section of a ini file ---------------------------------------- Command :command:`inifile_deletesection` will delete a section of a ini file and all of its content. .. code-block:: python inifile_deletesection("file.ini","global") Windows environment/ Software/ Services ======================================= Retrieving the version of a file -------------------------------- Command :command:`get_file_properties` shows package properties. .. code-block:: python get_file_properties(makepath(programfiles32,'InfraRecorder','infrarecorder.exe'))['ProductVersion'] Checking the Windows version ---------------------------- Command :command:`windows_version` checks that the Windows version is strictly inferior to *6.2.0*. .. code-block:: python windows_version()`_. Checking for 64bits architecture -------------------------------- Command :command:`iswin64` checks that the system architecture is 64bits. .. code-block:: python if iswin64(): print('Pc x64') else: print('Pc not x64') Checking for the Program Files variable --------------------------------------- * programfiles; .. code-block:: python print(programfiles()) * programfiles32; .. code-block:: python print(programfiles32()) * programfiles64; .. code-block:: python print(programfiles64()) Each command returns a different *ProgramFiles* location. For example, command :command:`programfiles64` returns native Program Files directory, eg. :file:`C:\\Program Files (x86)` on either win64 or win32 architecture and :command:`programfiles()` will return the path of the 32bit Program Files directory, eg. :file:`Programs Files (x86)` on win64 architecture, and :file:`Programs Files` on win32 architecture. Checking for the AppData variable --------------------------------- user_appdata/ user_local_appdata .. hint:: These functions are used with :command:`session_setup` Command :command:`user_appdata` returns roaming *AppData* profile path of logged on user (:file:`C:\\Users\\%username%\\AppData\\Roaming`). .. code-block:: python print(user_appdata()) Command :command:`user_local_appdata` returns the local *AppData* profile path of the logged on user (:file:`C:\\Users\\%username%\\AppData\\Local`). .. code-block:: python print(user_local_appdata()) Disabling temporarily the wow3264 file redirection -------------------------------------------------- Command :command:`disable_file_system_redirection` disables wow3264 redirection in the current context. .. code-block:: python with disable_file_system_redirection(): filecopyto('file.txt',system32()) Obtaining the current logged in user ------------------------------------ Command :command:`get_current_user` shows the currently logged on username. .. code-block:: python print(get_current_user()) Obtaining the computer name --------------------------- Command :command:`get_computername` shows the name of the computer. .. code-block:: python print(get_computername()) Obtaining the AD domain to which the computer is joined ------------------------------------------------------- Command :command:`get_domain_fromregistry` returns the :abbr:`FQDN (Fully Qualified Domain Name)` of the computer. .. code-block:: python get_domain_fromregistry() Actions on installed software ============================= Checking installed software --------------------------- Command :command:`installed_softwares` returns the list of installed software on the computer from registry in an array. .. code-block:: python installed_softwares('winscp') .. code-block:: python [{'install_location': u'C:\\Program Files\\WinSCP\\', 'version': u'5.9.2', 'name': u'WinSCP 5.9.2', 'key': u'winscp3_is1', 'uninstall_string': u'"C:\\Program Files\\WinSCP\\unins000.exe"', 'publisher': u'Martin Prikryl', 'install_date': u'20161102', 'system_component': 0}] Obtaining the uninstall command from registry --------------------------------------------- Command :command:`uninstall_cmd` returns the silent uninstall command. .. code-block:: python uninstall_cmd('winscp3_is1') .. code-block:: bash "C:\Program Files\WinSCP\unins000.exe" /SILENT Uninstalling software --------------------- .. code-block:: python for soft in installed_softwares('winscp'): if Version(soft['version']) < Version('5.9.2'): run(uninstall_cmd(soft['key'])) * For each item of the list return by *installed_softwares* containing keyword *winscp*. * If the version is lower than 5.9.2. * Then uninstall using the *uninstall_cmd* and specifying the corresponding *uninstallkey*. Killing tasks ------------- Command :command:`killalltasks` kills all tasks with the specified name. .. code-block:: python killalltasks('firefox') Using control file fields ========================= It is possible to use control file informations on :file:`setup.py`. Obtaining packages version -------------------------- .. code-block:: python def setup(): print(control['version']) Command :command:`print(control['version'])` shows the *version* value from the :file:`control` file. .. code-block:: python def setup(): print(control['version'].split('-',1)[0]) Command :command:`print(control['version'].split('-',1)[0])` shows the software version number without the WAPT version number from the :file:`control` file. Obtaining software title names ------------------------------ .. todo:: upcoming documentation Managing a WAPT package with another WAPT package ================================================= Installing a package -------------------- .. code-block:: python WAPT.install('tis-scratch') Command :command:`install` installs a WAPT package on the selected computer. Removing a package ------------------ .. code-block:: python WAPT.remove('tis-scratch') Command :command:`remove` uninstalls a WAPT package from the selected computer. Forgetting a package -------------------- .. code-block:: python WAPT.forget_packages('tis-scratch') Command :command:`forget_packages` informs the WAPT Agent to forget a WAPT package on the selected computer. .. hint:: If the desired result is to remove *tis-scratch*, you should either reinstall the package (:code:`wapt-get install "tis-scratch"`) then remove it (:command:`wapt-get remove "tis-scratch"`), either removing it manually from the Control Panel menu :menuselection:`Add/ Remove Programs`. ******************** Improving my package ******************** Copying a file ============== It is possible to configure :program:`Firefox` with a :file:`policies.json` file. See ``_. This file **MUST** be placed in the :file:`distribution` folder at the root of Firefox. To help you create this :file:`policies.json` file you can use the `enterprise policy generator `_ generator for Firefox. When you have generated your :file:`policies.json` file, place it in :file:`c:\\waptdev\\prefix-firefox-esr-wapt\\policies.json`. The :file:`distribution` folder at the root of Firefox may not exist, so we will test its existence and create it with the :command:`mkdirs` command if it does not exist: .. code-block:: python if not isdir(r'C:\Program Files\Mozilla Firefox\distribution'): mkdirs(r'C:\Program Files\Mozilla Firefox\distribution') .. important:: If you have backslashes in your path, you should always put an **r** in front of the string, like in the previous example. You will also need to use the ``filecopyto`` function to copy the :file:`policies.json` file: .. code-block:: python filecopyto('policies.json',r'C:\Program Files\Mozilla Firefox\distribution') .. hint:: There is no need to put the full path for the source file since the :file:`policies.json` file is at the root of the WAPT package, so we use the relative path. Modify your :file:`setup.py`: .. code-block:: python # -*- coding: utf-8 -*- from setuphelpers import * uninstallkey = [] def install(): install_exe_if_needed("Firefox Setup 45.5.0esr.exe",silentflags="-ms",key='Mozilla Firefox 45.5.0 ESR (x64 fr)',min_version="45.5.0") remove_desktop_shortcut('Firefox') if not isdir(r'C:\Program Files\Mozilla Firefox\distribution'): mkdirs(r'C:\Program Files\Mozilla Firefox\distribution') filecopyto('policies.json',r'C:\Program Files\Mozilla Firefox\distribution') Your package is now ready to apply a configuration. You can launch an installation with :program:`PyScripter` and validate that the package works according to your objective. Finally, launch your :program:`Firefox` to verify that it will work for your users. Uninstalling unwanted versions ============================== .. hint:: At each step of these examples you can run an installation to test the result. In our case we want to uninstall the non ESR version of :program:`Firefox`. We will look for the other software installed on the host to check if a non-esr version of :program:`Firefox` is installed. To reproduce our example, download and install the `latest consumer version of Firefox `_: * To search unwanted version of :program:`Firefox` we will use the ``installed_softwares`` function. This function returns a dictionary list containing the software properties: .. code-block:: python print(installed_softwares('Firefox')) [ { 'install_date': '', 'install_location': 'C:\\Program Files\\Mozilla Firefox', 'key': 'Mozilla Firefox 78.7.1 ESR (x64 fr)', 'name': 'Mozilla Firefox 78.7.1 ESR (x64 fr)', 'publisher': 'Mozilla', 'system_component': 0, 'uninstall_string': '"C:\\Program Files\\Mozilla Firefox\\uninstall\\helper.exe"', 'version': '78.7.1', 'win64': True }, { 'install_date': '', 'install_location': 'C:\Program Files (x86)\\Mozilla Firefox', 'key': 'Mozilla Firefox 79.0 (x86 fr)', 'name': 'Mozilla Firefox 79.0 (x86 fr)', 'publisher': 'Mozilla', 'system_component': 0, 'uninstall_string': '"C:\Program Files (x86)\\Mozilla Firefox\\uninstall\\helper.exe"', 'version': '79.0', 'win64': False } ] * Check the name of each software. .. code-block:: python for uninstall in installed_softwares('Mozilla Firefox'): print(uninstall['name']) * Show the name of each software found. .. code-block:: python for uninstall in installed_softwares('Mozilla Firefox'): if not 'ESR' in uninstall['name']: print(uninstall['name']) * Show the name of each software found which does not include the string *ESR* in its name and its uninstallkey. .. code-block:: python for uninstall in installed_softwares('Mozilla Firefox'): if not 'ESR' in uninstall['name']: print(uninstall['name']) print('Uninstall ' + uninstall['key']) We will now use a WAPT trick using the :command:`uninstall_cmd` function: * Install cmd accepts an uninstall key as an argument and will send the command to run to start the silent uninstall. .. code-block:: python for uninstall in installed_softwares('Mozilla Firefox'): if not 'ESR' in uninstall['name']: print(uninstall['name']) print('Uninstall ' + uninstall['key']) silent_uninstall = uninstall_cmd(uninstall['key']) print('Run ' + silent_uninstall) * Start the uninstallation. .. code-block:: python for uninstall in installed_softwares('Mozilla Firefox'): if not 'ESR' in uninstall['name']: print(uninstall['name']) print('Uninstall ' + uninstall['key']) silent_uninstall = uninstall_cmd(uninstall['key']) print('Run ' + silent_uninstall) run(silent_uninstall) We can also uninstall the Mozilla maintenance service: .. code-block:: python for uninstall in installed_softwares('MozillaMaintenanceService'): run(uninstall_cmd(uninstall['key'])) * Finally, modify your :file:`setup.py`: .. code-block:: python # -*- coding: utf-8 -*- from setuphelpers import * uninstallkey = [] def install(): #Install firefox if necessary install_exe_if_needed("Firefox Setup 45.5.0esr.exe",silentflags="-ms",key='Mozilla Firefox 45.5.0 ESR (x64 fr)',min_version="45.5.0") #Removal of the firefox shortcut on the all user desktop remove_desktop_shortcut('Firefox') #Creation of the distribution folder if it does not exist if not isdir(r'C:\Program Files\Mozilla Firefox\distribution'): mkdirs(r'C:\Program Files\Mozilla Firefox\distribution') #Copy of the policies.json file found at the root of the package in the destination of the distribution folder filecopyto('policies.json',r'C:\Program Files\Mozilla Firefox\distribution') #For each Mozilla Firefox installed for uninstall in installed_softwares('Mozilla Firefox'): #If the software does not have the word ESR in the name if not 'ESR' in uninstall['name']: print(uninstall['name']) print('Uninstall ' + uninstall['key']) #Looking for how we can uninstall it silently silent_uninstall = uninstall_cmd(uninstall['key']) print('Run ' + silent_uninstall) #We launch the previous command. run(silent_uninstall) #Uninstalling mozilla maintenance service for uninstall in installed_softwares('MozillaMaintenanceService'): run(uninstall_cmd(uninstall['key'])) Your code now handles the uninstallation of unwanted versions of :program:`Firefox`. Improving setup.py to use variables =================================== Examples of variable usage: .. code-block:: python version_firefox = "45.0" uninstallkey = "Mozilla Firefox " + version_firefox + " ESR (x64 fr)" print(uninstallkey) uninstallkey = "Mozilla Firefox %s ESR (x64 fr)" % (version_firefox) print(uninstallkey) uninstallkey = "Mozilla Firefox {} ESR (x64 fr)".format(version_firefox) print(uninstallkey) uninstallkey = f"Mozilla Firefox {version_firefox} ESR (x64 fr)" print(uninstallkey) .. important:: The last example is the best example but this operation only works with :program:`Python3`. We can now use variables in our :file:`setup.py`: .. code-block:: python # -*- coding: utf-8 -*- from setuphelpers import * uninstallkey = [] def install(): version_firefox = "45.5.0" #Install firefox if necessary install_exe_if_needed("Firefox Setup %sesr.exe" % version_firefox,silentflags="-ms",key='Mozilla Firefox %s ESR (x64 fr)' % version_firefox,min_version=version_firefox) #Removal of the firefox shortcut on the all user desktop remove_desktop_shortcut('Firefox') distribution_folder=r'C:\Program Files\Mozilla Firefox\distribution' #Creation of the distribution folder if it does not exist if not isdir(distribution_folder): mkdirs(distribution_folder) ... The rest of the code does not change ... .. hint:: You can retrieve the version number shown in the :file:`control` file like this: .. code-block:: python version_firefox = control.get_software_version() .. _user_session_setup: Customizing the user environment ================================ It is sometimes necessary to customize a software in user context to set specific settings or to comply to the Organization's rules and preferences: * Creating user desktop shortcut with specific arguments. * Making changes to user Windows registry keys. * Making changes to files, to browser settings of the user. * Configuring shortcuts to the Organization's set of templates for Documents, Spreadsheets or Presentations in Office Suites to encourage or insure that editorial and graphical guidelines are followed. * Setting up the user's email or instant messaging from the Organization's main user data repository (LDAP directory, database, etc). * Customizing an office suite or business software based on the Organization's main user data repository (LDAP directory, database, etc). The *session_setup* function benefits from the power of python to achieve a high level of automation. Principles of *session_setup* ----------------------------- The WAPT *session_setup* function is executed for each user using: .. code-block:: bash C:\Program Files (x86)\wapt\wapt-get.exe session-setup ALL Calling that function executes the *session_setup* script defined within each WAPT package installed on the computer. The WAPT Agent stores in its local database (:file:`C:\\Program Files (x86)\\wapt\\waptdb.sqlite`) the instruction sets of all WAPT packages. .. attention:: The *session_setup* script is launched only **once per WAPT package version and per user**. The WAPT Agent stores in is local :file:`%appdata%\\wapt\\waptsession.sqlite` database the instances of the *session_setup* scripts that have been already been played. Output example of :code:`wapt-get session-setup ALL`: .. note:: The logged in user *session_setup* has already previously been launched. .. code-block:: bash wapt-get session-setup ALL Configuring tis-7zip ... No session-setup. Done Configuring tis-ccleaner ... Already installed. Done Configuring tis-vlc ... No session-setup. Done Configuring tis-tightvnc ... No session-setup. Done Configuring tis-paint.net ... No session-setup. Done Configuring wsuser01.mydomain.lan ... No session-setup. Done Using *session_setup* --------------------- The *session_setup* scripts are located in the section *def session_setup()* of the :file:`setup.py` file: Example: .. code-block:: python def session_setup(): registry_setstring(HKEY_CURRENT_USER, "SOFTWARE\\Microsoft\\Windows Live\\Common",'TOUVersion','16.0.0.0', type=REG_SZ) .. attention:: With :command:`session_setup`, there is no possibility to call files contained inside the WAPT package. To call external files when uninstalling, copy and paste the needed files in an external folder during the package installation process (example: :file:`c:\\cachefile`). Example: creating a personalized desktop shortcut ------------------------------------------------- One of the possibilities offered by :term:`Setuphelpers` is adding personalized shortcuts on user desktops, instead of a desktop shortcut common to all users. For that purpose, we will use the :code:`create_user_desktop_shortcut()` function to create shortcuts containing the username and passing a website as an argument to Firefox. .. code-block:: python :emphasize-lines: 9-10 # -*- coding: utf-8 -*- from setuphelpers import * uninstallkey = [] def install(): install_exe_if_needed("Firefox Setup 45.5.0esr.exe",silentflags="-ms",key='Mozilla Firefox 45.4.0 ESR (x64 fr)',min_version="45.5.0") def session_setup(): create_user_desktop_shortcut("Mozilla Firefox de %s" % get_current_user(),r'C:\Program Files\Mozilla Firefox\firefox.exe',arguments="-url https://tranquil.it") * Now start the ``session-setup`` directly from :program:`PyScripter`. .. figure:: wapt-resources/windows_pyscripter_run-session-setup_menu-item.png :align: center :alt: PyScripter - running session-setup PyScripter - running session-setup * Finally, check that the icon is present on the desktop. .. _auditing_packages_for_compliance: Using the audit functions for compliance ======================================== .. note:: This feature is available in the **Enterprise** version. The audit function allows to make regular checks to desktop configurations and to centralize the results of these checks in the WAPT Console. This feature allows you to ascertain that your installed base of hosts matches your set of conformity rules over time. For example you can: * Regularly check the list of local administrators on the desktops. * Ascertain over time the correct configuration of a critical software. * Regularly check the presence of the correct version of a piece of software. * Ascertain the security settings of a workstation. The :code:`audit` function benefits from the depth and the breadth of python libraries for unmatched levels of precision and finesse for your auditing needs. Working principle ----------------- The :code:`audit` tasks are launched once after every :command:`wapt-get upgrade`, then regularly as defined by the :code:`audit_schedule` attribute. To manually launch an audit check, you may also use the following command: .. code-block:: bash wapt-get audit .. note:: By default, the :code:`audit` function will not launch if the audit is not necessary. To force the execution, you may launch the following command: .. code-block:: bash wapt-get audit -f The :code:`audit` script is defined in the package's :file:`setup.py` with a function :code:`def audit()`: In this example, we are improving the Firefox package previously studied in this documentation. * Add the :code:`audit` function in the :file:`setup.py`. .. code-block:: python def audit(): if isfile(r'C:\Program Files\Mozilla Firefox\distribution\policies.json'): print('File policies.json found') return "OK" else: print('File policies.json not found') return "ERROR" * Start the audit from :program:`PyScripter`. .. image:: wapt-resources/windows_pyscripter_run-audit_menu-item.png :align: center :alt: PyScripter - Running an audit * Test with the file then delete the :file:`C:\\Program Files\\Mozilla Firefox\\distribution\\policies.json` file and test again with :program:`PyScripter`. You can directly see the status of the audit in the WAPT Console (Click on the package then on the audit column): .. figure:: wapt-resources/wapt_console_audit_container-window.png :align: center :alt: Checking an audit status in the WAPT Console Checking an audit status in the WAPT Console The audit function returns one of these 3 values: * **OK**; * **WARNING**; * **ERROR**. .. attention:: With the *audit* function, it is not possible to use files that are contained in the WAPT packages. To use files embedded in the WAPT package that will be used for an audit, you **MUST** instruct to copy the file(s) to a temporary folder when the WAPT package installs. Planning an audit ----------------- The *audit* tasks are launched once after every *upgrade*, then regularly as defined with the :code:`audit_schedule` value. The value is contained in the :file:`control` file of the WAPT package. By default, if :code:`audit_schedule` is empty, the audit task can be launched manually from the WAPT Console or be launched automatically if you have defined the option :code:`waptaudit_task_period` in the :file:`wapt-get.ini` of the WAPT Agent. For more information about the last method, please see :ref:`this documentation `. Otherwise, the periodicity may be indicated in several ways: * An integer (in minutes). * An integer followed by a letter (m = minutes, h = hours , d = days , w = weeks). Default behavior of the audit function -------------------------------------- By default, the only audit function checks the presence of *UninstallKey* for its WAPT package. This way, WAPT ascertains that the software is still present on the host, according to the host configuration. .. _manipulate_audit_data: Auditing configurations to insure compliance ============================================ .. note:: This feature is available in the **Enterprise** version. The :code:`audit_data` function allows to make regular checks to desktop configurations and to centralize the results of these checks in the WAPT Console. There is historization and you can encrypt your data and decrypt it with your WAPT certificate. For example you can: * Change an administrator password, encrypt information and display it on your WAPT Console. * Regularly check the modification your computer needs like CVE or GLPI inventory. * Ascertain the security settings of a workstation and historize issues. The :code:`audit_data` function is usable in the :code:`audit` function only. Working principle ----------------- The :code:`audit_data` functions are launched if they are defined in the :code:`def audit()` section of the :file:`setup.py` file. On the server side, audit data is stored in the HostAuditData table. The content of the table can be queried using the :guilabel:`Reporting` tab in the WAPT Console. The Data is automatically purged according to expiration date. When WAPT host :code:`update_status()` is launched, the newer audit data is sent to the WAPT Server. On the Client side, the audit data is stored in the host database with an expiration date (date_expiration) and the max count (max_count) of the stored data is defined in the code. In this example, we are checking public IP on the computer. * Add the :code:`audit_data` function inside the :code:`audit` function in the :file:`setup.py`. .. code-block:: python def audit(): ip = wgets('https://api.ipify.org',verify_cert=False) print(f'My public IP address is: {ip}') WAPT.write_audit_data_if_changed('Public IP','log for %s' % get_computername(),ip,max_count=5) return 'OK' Here are the functions related to :code:`audit_data`: .. code-block:: python def write_audit_data_if_changed(self, section, key, value, ptype=None, value_date=None, expiration_date=None, max_count=2, keep_days=None): """Write data only if different from last one """ def write_audit_data(self, section, key, value, ptype=None, value_date=None, expiration_date=None, max_count=2, keep_days=None): """Stores in database a metrics, removes expired ones Args: section (str) key (str) value (any) value_date expiration_date (str) : expiration date of the new value max_count (int) : keep at most max_count value. remove oldest one. keep_days (int) : set the expiration date to now + keep_days days. override expiration_date arg if not None Returns: None """ def read_audit_data(self, section, key, default=None, ptype=None): """Retrieve the latest value associated with section/key from database""" def read_audit_data_set(self, section, key): """Retrieve all the values associated with section/key from database""" def delete_audit_data(self, section, key): def read_audit_data_since(self, last_query_date=None): """Retrieve all the values since a date from database""" .. _def_update: Updating automatically a software package ========================================= .. note:: This part of the documentation is for advanced users of WAPT. The :code:`update_package` functions are very practical, they allow to gain a lot of time when needing to update a WAPT package with the most recent version of a piece of software. Working principle ----------------- The *update_package* function will: * Fetch online the latest version of the software. * Download the latest version of the software binaries. * Remove old versions of the software binaries. * Update the version number of the software in the :file:`control` file. If you base your *install* function on the version number inside the :file:`control` file, then you do not even need to modify your :file:`setup.py`. You just have to do your usual Quality Assurance tests before you :command:`build-upload` your new package. Example ------- Here is the *update_package* script for :program:`firefox-esr` as an example: .. code-block:: python def update_package(): import re,requests,glob #Retrieving the last file name url = requests.head('https://download.mozilla.org/?product=firefox-esr-latest&os=win64',proxies={}).headers['Location'] filename = url.rsplit('/',1)[1].replace('%20',' ') #download of it if is not in the package if not isfile(filename): print('Downloading %s from %s'%(filename,url)) wget(url,filename) #removing old exe with wrong name for fn in glob.glob('*.exe'): if fn != filename: remove_file(fn) # updates control version from filename, increment package version. control.version = '%s-0'%(re.findall('Firefox Setup (.*)esr\.exe',filename)[0]) control.save_control_to_wapt() You may launch the *update_package* in :program:`PyScripter`: .. figure:: wapt-resources/windows_pyscripter_run-update-package-source_menu-item.png :align: center :alt: PyScripter - Running an update-package-source PyScripter - Running an update-package-source You will find many inspiring examples of *update_package* scripts in packages hosted in the `Tranquil IT store `_. .. _installing_portable_software: Deploying a portable software with WAPT ======================================= A good example of a WAPT package is a self-contained/ *portable* software package: * Create the folder for the software in :file:`C:\\Program Files (x86)`. * Copy the software in that folder. * Create the shortcut to the application. * Manage the uninstallation process for the application. * Close the application if it is running. Example with ADWCleaner ----------------------- First, download `Adwcleaner `_. You can then generate your package template, please refer to the :ref:`documentation for creating packages from the WAPT Console `. The file :file:`C:\\waptdev\\tis-adwcleaner-wapt` is created. Here you will find an example of a portable package that takes almost all the WAPT functions of a :file:`setup.py`: .. code-block:: python from setuphelpers import * uninstallkey = [] exe_name = 'AdwCleaner.exe' path_adw = makepath(programfiles,'AdwCleaner') path_exe = makepath(path_adw,exe_name) nameshortcut = 'AdwCleaner' def install(): mkdirs(path_adw) filecopyto(exe_name,path_exe) create_desktop_shortcut(nameshortcut,path_exe) def uninstall(): remove_tree(path_adw) remove_desktop_shortcut(nameshortcut,path_exe) def audit(): if not isfile(path_exe): print('File not found') return "OK" else: print('File Found') return "ERROR" def update_package(): wget('https://downloads.malwarebytes.com/file/AdwCleaner',exe_name) control.version = get_file_properties(exe_name)['FileVersion'] + '-0' control.save_control_to_wapt() .. _simple_msu_packaging: Packaging Windows Update .msu packages ====================================== .. hint:: Pre-requisites: to build WAPT packages, :ref:`the WAPT development environment MUST be installed `. Between *Patch Tuesday* releases, Microsoft may release additional KBs or critical updates that will need to be pushed to hosts quickly. For that purpose, WAPT provides a package template for :mimetype:`.msu` files. In that example, we use the KB4522355 downloaded from Microsoft Catalog website. * `Download KB4522355 MSU package from Microsoft Catalog website `_. * Create a WAPT package template from the downloaded :mimetype:`.msu` file. In the WAPT Console, click on :menuselection:`Tools --> Package Wizard`. .. figure:: wapt-resources/wapt_console_make-package-template_menu-option.png :align: center :alt: PyScripter - WAPT Console window for creating a package template PyScripter - WAPT Console window for creating a package template * Select the downloaded :mimetype:`.msu` package and fill in the required fields. .. figure:: wapt-resources/wapt_console_package-wizard-msu_dialog-box.png :align: center :alt: Informations required for creating the MSU package Informations required for creating the MSU package * Click on :guilabel:`Make and edit` (recommended) to launch package customization. * WAPT package IDE is launched using the source code from the pre-defined :mimetype:`.msu` template. * As usual with WAPT packages, test, then build, then sign, then upload and finally affect the desired WAPT packages to your selected hosts and it is done!! * If the KB becomes bundled with the following *Patch Tuesday*, you can select the hosts onto which the package has been applied and forget the KB package on the hosts. .. _linux_packaging: Packaging simple Linux packages =============================== Before starting, we assume several conditions: * You have a graphical interface on your Linux system that you use for developing and testing packages. * You have installed the :program:`vscode` package from the Tranquil IT repository. * Your user is named *linuxuser* and is a member of the *sudoers* group. Creating a base template from you linux computer ------------------------------------------------ * Start up a Command Line utility. * As *linuxuser*, create a WAPT package template. .. code-block:: bash wapt-get make-template .. warning:: **Do not launch this command as root or with a sudo.** When you create a template, there will be several files in the :mimetype:`.vscode` folder inside the WAPT package folder: * :file:`settings.json`; * :file:`launch.json`. Example with :program:`VLC`: .. code-block:: bash wapt-get make-template "tis-vlc" Using config file: /opt/wapt/wapt-get.ini Template created. You can build the WAPT package by launching /opt/wapt//wapt-get.py build-package /home/linuxuser/waptdev/tis-vlc-wapt You can build and upload the WAPT package by launching /opt/wapt//wapt-get.py build-upload /home/linuxuser/waptdev/tis-vlc-wapt .. hint:: All WAPT packages are stored in *linuxuser*'s home (home of the currently logged in user). * VSCode loads up and opens the WAPT package project. .. figure:: wapt-resources/windows_vscode_vlc_text-terminal-window.png :align: center :alt: VSCode opening with focus on the *setup* file VSCode opening with focus on the *setup* file * Check the :file:`control` file content. You have to give a :code:`description` to the WAPT package, define the :code:`os_target` and the :code:`version` of the WAPT package. .. hint:: :code:`os_target` for unix is *linux*. .. warning:: The software :code:`version` number in your :file:`control` file **MUST** start at 0, and not the version number of the software title, as the version number may not be the same as displayed in the DEB / YUM repository. * Original :file:`control` file. .. literalinclude:: wapt-resources/package-linux-control_origin.txt :emphasize-lines: 2 * Modified :file:`control` file. .. literalinclude:: wapt-resources/package-linux-control_modified.txt :emphasize-lines: 2,6,7 .. note:: It is to be noted that a sub-version *-1* has been added. It is the packaging version of the WAPT package. It allows the WAPT package Developer to release several WAPT package versions of the same software, very useful for very rapid and iterative development. * Make changes to the code in the :file:`setup.py` file accordingly. .. code-block:: python :emphasize-lines: 8 # -*- coding: utf-8 -*- from setuphelpers import * uninstallkey = [] def install(): apt_install('vlc') * Save the package. Managing the uninstallation --------------------------- * Make changes to the :file:`setup.py` file with an uninstall. .. code-block:: python def uninstall(): apt_remove('vlc') * Launch a :guilabel:`remove` from VSCode :guilabel:`Run Configurations`. .. figure:: wapt-resources/windows_vscode_package_menu-item.png :align: center :alt: After uninstallation, the software is correctly removed After uninstallation, the software is correctly removed * Check that the software has been correctly removed. .. code-block:: bash dpkg -l | grep vlc .. hint:: In the :command:`uninstall()` function, it is not possible to call for files included inside the WAPT package. To call files from the package, it is necessary to copy/ paste the files in a temporary directory during package installation. Managing the session-setup -------------------------- * Make changes to the :file:`setup.py` file with a :code:`session-setup`; In this example, we will create a file :file:`vlcrc` by default in the user profile. .. code-block:: python def session_setup(): vlcrc_content="""[qt] # Qt interface qt-notification=0 qt-privacy-ask=0 metadata-network-access=0 """ vlcdir = os.path.join(os.environ['HOME'], '.config', 'vlc') path_vlrc = makepath(vlcdir,'vlcrc') ensure_dir(vlcdir) if not isfile(path_vlrc): with open(makepath(vlcdir,'vlcrc')) as f: f.write(vlcrc_content) * Launch a :guilabel:`session-setup` from VSCode :guilabel:`Run Configurations`. .. figure:: wapt-resources/windows_vscode_package_menu-item.png :align: center :alt: After uninstallation, the software is correctly removed After uninstallation, the software is correctly removed Building and uploading the WAPT package --------------------------------------- You will find the WAPT package in your :file:`~/waptdev` folder. You need to transfer the WAPT package folder to the Windows host that has the private key that you use to sign your WAPT packages. Then, please refer to the :ref:`documentation for building and uploading packages from the WAPT Console `. .. _encryting_sensitive_data_in_package: Encrypting sensitive data contained in a WAPT package ===================================================== .. note:: This part of the documentation is for advanced users of WAPT. This feature is available only in the **Enterprise** version. What is the purpose for doing that? ----------------------------------- With WAPT, the integrity of the package is ensured. A package whose content has been modified without being re-signed will systematically be refused by the WAPT client. On the other hand, the content of a WAPT package is not encrypted and will be readable by everyone. This technical model of transparency brings nevertheless many benefits. This can be annoying in the case of a package that contains a password, a license key, or any sensitive or confidential data. Fortunately, **we have a solution**! Working principle ----------------- When a WAPT Agent registers with the WAPT Server, it generates a private key/ public certificate pair in :file:`C:\\Program Files (x86)\\wapt\\private`. * The certificate is sent to the WAPT Server with the inventory when the WAPT client is first registered. * The private key is kept by the Agent and is only readable locally by the :term:`Local Administrators`. We will therefore encrypt the sensitive data contained inside the package with the certificate belonging to the host. During installation, the WAPT Agent will be able to decrypt the sensitive data using its private key. With this mode of operation, the WAPT Server and secondary repositories have no knowledge of the sensitive data. Practical case -------------- You will find here an example of a WAPT package where we encrypt a string of text in an :command:`update_package` function and then decrypt this text in the :command:`install` function. In this example, the :command:`update_package` function allows us to browse the WAPT Server database to retrieve the certificate from each host and then encrypt the sensitive text with it. The encrypted text for each host is then stored in a :file:`encrypt-txt.json` file at the root of the WAPT package. When the WAPT package installs, the WAPT Agent will take the encrypted text and decipher it with his own private key. You can test it by yourself by downloading the example package `tis-encrypt-sample `_. .. attention:: The python output (log install of the WAPT package) is readable by the users on the host, so **you should not display the deciphered text with a print during installation**. .. _envdev_setup: .. _using_different_development_environments: ################################################# Using different IDEs for developing WAPT packages ################################################# ************************************** Configuring WAPT to use supported IDEs ************************************** If you are used to work with another :term:`IDE`, you can be relieved now as WAPT supports many popular text editors. .. note:: Using a supported IDE will launch the WAPT package project with a valid debug configuration. On Windows ========== .. list-table:: Natively supported text editors in WAPT on Windows :header-rows: 1 :widths: 50, 50 * - Text editor name - Text editor logo * - :program:`PyScripter` - |pyscripter| * - :program:`Visual Studio Code` - |vscode| * - :program:`Visual Studio Codium` - |vscodium| To configure another editor for WAPT, you **MUST** modify the :code:`editor_for_packages` attribute in the ``[global]`` section of your WAPT Console's :file:`%LOCALAPPDATA%\\waptconsole\\waptconsole.ini` configuration file. .. code-block:: ini [global] ... editor_for_packages = vscode On Linux / macOS ================ .. list-table:: Natively supported text editors in WAPT on Windows :header-rows: 1 :widths: 50, 50 * - Text editor name - Text editor logo * - :program:`Visual Studio Code` - |vscode| * - :program:`Visual Studio Codium` - |vscodium| * - :program:`Nano` - |nano| * - :program:`Vim` - |vim| To configure another editor for WAPT, you **MUST** modify the :code:`editor_for_packages` attribute in the ``[global]`` section of your WAPT Agent configuration file: :file:`/opt/wapt/wapt-get.ini`. By default, if the :code:`editor_for_packages` attribute is empty, WAPT will try to launch (in that order): * :program:`vscodium`; * :program:`vscode`; * :program:`nano`; * :program:`vim`; * :program:`vi`. .. code-block:: ini [global] ... editor_for_packages = vim *************************************** Configuring WAPT to use a custom editor *************************************** .. tabs:: .. code-tab:: ini Windows [global] ... editor_for_packages = C:\Program Files\Notepad++\notepad++.exe {setup_filename} .. code-tab:: ini Linux/ macOS [global] ... editor_for_packages = /opt/pycharm/bin/pycharm_x64 {wapt_sources_dir} Custom arguments ================ .. list-table:: Arguments for the :code:`editor_for_packages` option :header-rows: 1 :widths: 50 50 * - Argument - Description * - :code:`{setup_filename}` - Launches custom editor and edit WAPT package :file:`setup.py` file. * - :code:`{control_filename}` - Launches custom editor and edit WAPT package :file:`control` file. * - :code:`{wapt_sources_dir}` - Launches the custom text editor and opens the WAPT package folder. * - :code:`{wapt_base_dir}` - Launches the custom text editor and opens the WAPT install folder.