igneum/relay/playbooks/wsl-setup.ps1
igneum-labs 1065b81d05 relay: three auth tiers, signed run tasks, machine secrets, retention; clients on headers; TZ=UTC and curl -K checks (X23 X24 X25 X26 X27 X28 X29 G13 G14)
Relay (X23, X27): the intake key is its own tier (upload and file drops only, RELAY_INTAKE_COMPAT=0 closes it);
a run task needs an Ed25519 signature by the Mac run key over {to, nonce, body sha256, flags} (RELAY_RUN_PUB,
401 without) and an HMAC tag with the target's machine secret that the agent verifies before anything runs;
results and registration are bound to the machine the secret proves (403 on a forged from).
X24: every client and Mac tool sends x-relay-token as a header to /api/relay?fn=; the path token stays for the
phone page only. X25: the agent arms the logon task only for a restart a task asked for and disarms on start
and exit. X26: 30-day retention with blob deletion, feed capped at 100, the dl base as RELAY_DL_BASE held by the
agent, never in a body. X28: GET inbox never acks (POST inbox does), RELAY-REBOOT on its own line and only with a
reboot flag, 120/min and 10 failed auths/min per IP, no username or folder on register, WSL sudo scoped to
apt-get and dpkg with SETENV, no password on a command line. X29: the intake key reaches curl through -K in
upload.sh and both upload-log.bat; tools/ci/curl-header-check.sh fails the class. G14: TZ=UTC in ship-app.mjs
and publish-jobs.sh; tools/ci/commit-tz-check.sh fails the class; history-rewrite.md names the .old-2026-10-05
files as the values in the history. The handler moved to relay/lib/handler.mjs with injected sql and blobs
(relay/lib/blob.mjs holds @vercel/blob) so relay/test/handler.test.mjs drives it without a database:
47 tests across 6 suites, all green.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:46:13 +00:00

58 lines
3.8 KiB
PowerShell

# Igneum playbook: WSL2 + Ubuntu 24.04 with a ready `igneum` user, no questions asked. Two passes around one reboot.
# Queue from the Mac: node tools/relay.mjs run PC2 "wsl setup" relay/playbooks/wsl-setup.ps1 --elevated --reboot-continue
# Pass 1: hypervisor on, VirtualMachinePlatform + WSL features, prints RELAY-REBOOT on its own line (the agent reboots
# only because the task was queued with --reboot-continue, and re-arms for that one restart).
# Pass 2: wsl --install Ubuntu-24.04 --no-launch, creates the user igneum (password igneum; sudo without a password for
# apt-get and dpkg only, with SETENV for DEBIAN_FRONTEND, which is all setup-wsl.sh needs: X28, no blanket sudo),
# makes it the default, checks the GPU is visible inside WSL.
# UNTESTED on a PC as of 4 Oct 2026: written from the wsl.exe and dism.exe documentation; expect a first-run fix.
$ErrorActionPreference = 'Continue'
$distro = 'Ubuntu-24.04'
$pass = 1; if ($env:RELAY_PASS) { $pass = [int]$env:RELAY_PASS }
$markerDir = Join-Path $env:ProgramData 'igneum'; New-Item -ItemType Directory -Force -Path $markerDir | Out-Null
$marker = Join-Path $markerDir 'wsl-setup.pass1'
function Strip([string] $s) { if ($null -eq $s) { return '' }; return ($s -replace "`0", '') }
Write-Host "wsl-setup pass $pass on $env:COMPUTERNAME"
$installed = $false
try { $list = Strip (((& wsl.exe --list --quiet 2>&1) | Out-String)); if ($list -match 'Ubuntu-24\.04') { $installed = $true } } catch {}
if ($pass -le 1 -and -not (Test-Path $marker) -and -not $installed) {
Write-Host 'pass 1: hypervisor + features'
& bcdedit.exe /set hypervisorlaunchtype auto
& dism.exe /online /enable-feature /featurename:VirtualMachinePlatform /all /norestart
& dism.exe /online /enable-feature /featurename:Microsoft-Windows-Subsystem-Linux /all /norestart
Set-Content -Path $marker -Value (Get-Date -Format o)
Write-Host 'features enabled; a restart is needed before Ubuntu can be installed'
Write-Host 'RELAY-REBOOT'
exit 0
}
Write-Host 'pass 2: WSL kernel, Ubuntu 24.04, the igneum user'
& wsl.exe --update 2>&1 | ForEach-Object { Strip "$_" }
& wsl.exe --set-default-version 2 2>&1 | ForEach-Object { Strip "$_" }
if (-not $installed) {
& wsl.exe --install -d $distro --no-launch 2>&1 | ForEach-Object { Strip "$_" }
Start-Sleep 5
}
$list = Strip (((& wsl.exe --list --verbose 2>&1) | Out-String)); Write-Host $list
if ($list -notmatch 'Ubuntu-24\.04') { Write-Host "ERROR: $distro is not registered after the install"; exit 2 }
$mk = 'id igneum >/dev/null 2>&1 || (useradd -m -s /bin/bash igneum && echo igneum:igneum | chpasswd && usermod -aG sudo igneum); ' +
'echo "igneum ALL=(root) NOPASSWD:SETENV: /usr/bin/apt-get, /usr/bin/dpkg" > /etc/sudoers.d/igneum && chmod 440 /etc/sudoers.d/igneum && visudo -cf /etc/sudoers.d/igneum; ' +
'printf "[user]\ndefault=igneum\n[boot]\nsystemd=true\n" > /etc/wsl.conf; id igneum'
& wsl.exe -d $distro -u root -- bash -c $mk 2>&1 | ForEach-Object { Strip "$_" }
& wsl.exe --terminate $distro 2>&1 | Out-Null
$wslconfig = Join-Path $env:USERPROFILE '.wslconfig'
if (-not (Test-Path $wslconfig)) {
$ramGb = [math]::Floor((Get-CimInstance Win32_ComputerSystem).TotalPhysicalMemory / 1GB)
$give = [math]::Max(16, [math]::Floor($ramGb * 0.75))
"[wsl2]`nmemory=${give}GB`nswap=16GB`n" | Set-Content -Path $wslconfig -Encoding ascii
Write-Host "wrote $wslconfig (memory=${give}GB of $ramGb GB)"
& wsl.exe --shutdown 2>&1 | Out-Null
}
Write-Host 'check: user, kernel, GPU inside WSL'
& wsl.exe -d $distro -- bash -lc 'id; uname -r; nvidia-smi --query-gpu=name,driver_version --format=csv,noheader 2>/dev/null || ls -l /usr/lib/wsl/lib/libcuda.so.1 2>/dev/null || echo "no GPU visible inside WSL (update the Windows NVIDIA driver, then wsl --update)"' 2>&1 | ForEach-Object { Strip "$_" }
Write-Host 'wsl-setup done'
exit 0