From f0db2a227bd3835b70323fd784767d013df736bf Mon Sep 17 00:00:00 2001 From: igor04091968 Date: Thu, 7 May 2026 19:22:05 +0300 Subject: [PATCH] revert(pssa): restore validate-deployment.ps1 from commit 63904d2 (stable) Restored clean version to fix corruption introduced earlier. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- windows/validate-deployment.ps1 | 396 ++------------------------------ 1 file changed, 23 insertions(+), 373 deletions(-) diff --git a/windows/validate-deployment.ps1 b/windows/validate-deployment.ps1 index 7c06f5a..15a4822 100644 --- a/windows/validate-deployment.ps1 +++ b/windows/validate-deployment.ps1 @@ -1,6 +1,6 @@ -[CmdletBinding()] +[CmdletBinding()] param( - [string]$ConfigPath = 'C:\ProgramData\AWatch-rus\deployment-config.json' + [string]$ConfigPath = 'C:\ProgramData\ActivityWatch\deployment-config.json' ) Set-StrictMode -Version Latest @@ -13,101 +13,26 @@ $config = Read-ActivityWatchDeploymentConfig -Path $ConfigPath $installRoot = [string]$config.paths.installRoot $stateRoot = [string]$config.paths.stateRoot $collectorScript = [string]$config.paths.collectorScript -$endpointCollectorScript = if ($config.paths.PSObject.Properties.Name -contains 'endpointCollectorScript') { [string]$config.paths.endpointCollectorScript } else { Join-Path $stateRoot 'dlp-endpoint-signals-collector.ps1' } -$fileCollectorScript = if ($config.paths.PSObject.Properties.Name -contains 'fileCollectorScript') { [string]$config.paths.fileCollectorScript } else { Join-Path $stateRoot 'file-operations-collector.ps1' } -$sessionCollectorScript = if ($config.paths.PSObject.Properties.Name -contains 'sessionCollectorScript') { [string]$config.paths.sessionCollectorScript } else { Join-Path $stateRoot 'worktime-session-collector.ps1' } $rulesPath = [string]$config.paths.rulesPath -$policyPath = if ($config.paths.PSObject.Properties.Name -contains 'policyPath') { [string]$config.paths.policyPath } else { Join-Path $stateRoot 'dlp-policy.json' } $launchScript = [string]$config.paths.launchScript $recoveryScript = [string]$config.paths.recoveryScript -$afkExpected = if ($config.PSObject.Properties.Name -contains 'collectors' -and $config.collectors.PSObject.Properties.Name -contains 'afkEnabled') { [bool]$config.collectors.afkEnabled } else { $true } -$windowExpected = if ($config.PSObject.Properties.Name -contains 'collectors' -and $config.collectors.PSObject.Properties.Name -contains 'windowEnabled') { [bool]$config.collectors.windowEnabled } else { $true } -$fileOpsExpected = if ($config.PSObject.Properties.Name -contains 'collectors' -and $config.collectors.PSObject.Properties.Name -contains 'fileOpsEnabled') { [bool]$config.collectors.fileOpsEnabled } else { $true } -$printServiceOperationalEnabled = $false -try { - $printServiceLog = Get-WinEvent -ListLog 'Microsoft-Windows-PrintService/Operational' -ErrorAction Stop - $printServiceOperationalEnabled = [bool]$printServiceLog.IsEnabled -} -catch { Write-Error [CmdletBinding()] -param( - [string]$ConfigPath = 'C:\ProgramData\AWatch-rus\deployment-config.json' -) - -Set-StrictMode -Version Latest -$ErrorActionPreference = 'Stop' - -$modulePath = Join-Path $PSScriptRoot 'ActivityWatch.Windows.Common.psm1' -Import-Module $modulePath -Force - -$config = Read-ActivityWatchDeploymentConfig -Path $ConfigPath -$installRoot = [string]$config.paths.installRoot -$stateRoot = [string]$config.paths.stateRoot -$collectorScript = [string]$config.paths.collectorScript -$endpointCollectorScript = if ($config.paths.PSObject.Properties.Name -contains 'endpointCollectorScript') { [string]$config.paths.endpointCollectorScript } else { Join-Path $stateRoot 'dlp-endpoint-signals-collector.ps1' } -$fileCollectorScript = if ($config.paths.PSObject.Properties.Name -contains 'fileCollectorScript') { [string]$config.paths.fileCollectorScript } else { Join-Path $stateRoot 'file-operations-collector.ps1' } -$sessionCollectorScript = if ($config.paths.PSObject.Properties.Name -contains 'sessionCollectorScript') { [string]$config.paths.sessionCollectorScript } else { Join-Path $stateRoot 'worktime-session-collector.ps1' } -$rulesPath = [string]$config.paths.rulesPath -$policyPath = if ($config.paths.PSObject.Properties.Name -contains 'policyPath') { [string]$config.paths.policyPath } else { Join-Path $stateRoot 'dlp-policy.json' } -$launchScript = [string]$config.paths.launchScript -$recoveryScript = [string]$config.paths.recoveryScript - -$afkExpected = if ($config.PSObject.Properties.Name -contains 'collectors' -and $config.collectors.PSObject.Properties.Name -contains 'afkEnabled') { [bool]$config.collectors.afkEnabled } else { $true } -$windowExpected = if ($config.PSObject.Properties.Name -contains 'collectors' -and $config.collectors.PSObject.Properties.Name -contains 'windowEnabled') { [bool]$config.collectors.windowEnabled } else { $true } -$fileOpsExpected = if ($config.PSObject.Properties.Name -contains 'collectors' -and $config.collectors.PSObject.Properties.Name -contains 'fileOpsEnabled') { [bool]$config.collectors.fileOpsEnabled } else { $true } -$printServiceOperationalEnabled = $false -try { - $printServiceLog = Get-WinEvent -ListLog 'Microsoft-Windows-PrintService/Operational' -ErrorAction Stop - $printServiceOperationalEnabled = [bool]$printServiceLog.IsEnabled -} -catch { -} -$printJobTitlePolicyEnabled = $false -try { - $printPolicy = Get-ItemProperty -LiteralPath 'HKLM:\Software\Policies\Microsoft\Windows NT\Printers' -Name 'ShowJobTitleInEventLogs' -ErrorAction Stop - $printJobTitlePolicyEnabled = ([int]$printPolicy.ShowJobTitleInEventLogs -eq 1) -} -catch { -} $requiredFiles = @( + (Join-Path $installRoot 'aw-watcher-afk\aw-watcher-afk.exe'), + (Join-Path $installRoot 'aw-watcher-window\aw-watcher-window.exe'), $collectorScript, - $endpointCollectorScript, - $sessionCollectorScript, $rulesPath, - $policyPath, $launchScript, $recoveryScript, $ConfigPath ) -if ($fileOpsExpected) { - $requiredFiles += $fileCollectorScript -} -if ($afkExpected) { - $requiredFiles += (Join-Path $installRoot 'aw-watcher-afk\aw-watcher-afk.exe') -} -if ($windowExpected) { - $requiredFiles += (Join-Path $installRoot 'aw-watcher-window\aw-watcher-window.exe') -} $missingFiles = @( $requiredFiles | Where-Object { -not (Test-Path -LiteralPath $_) } ) -$processNames = @() -if ($afkExpected) { $processNames += 'aw-watcher-afk' } -if ($windowExpected) { $processNames += 'aw-watcher-window' } -$runningProcesses = @() -if ($processNames.Count -gt 0) { - $runningProcesses = Get-Process -Name $processNames -ErrorAction SilentlyContinue | Select-Object Name, Id, SessionId -} -$sessionCollectorProcesses = @( - Get-CimInstance Win32_Process -ErrorAction SilentlyContinue | - Where-Object { - ($_.Name -ieq 'powershell.exe' -or $_.Name -ieq 'pwsh.exe') -and - $_.CommandLine -match [Regex]::Escape($sessionCollectorScript) - } | - Select-Object Name, ProcessId, SessionId, CommandLine -) +$processNames = @('aw-watcher-afk', 'aw-watcher-window') +$runningProcesses = Get-Process -Name $processNames -ErrorAction SilentlyContinue | Select-Object Name, Id, SessionId $taskNames = @() if ($config.userTasks) { @@ -116,28 +41,25 @@ if ($config.userTasks) { $taskNames += [string]$config.recovery.taskName $taskNames = $taskNames | Sort-Object -Unique -$tasks = @( - foreach ($taskName in $taskNames) { - $task = Get-ScheduledTask -ErrorAction SilentlyContinue | Where-Object { $_.TaskName -eq $taskName } | Select-Object -First 1 - if ($task) { - [pscustomobject]@{ - taskName = $task.TaskName - state = [string]$task.State - present = $true - } - } - else { - [pscustomobject]@{ - taskName = $taskName - state = 'Отсутствует' - present = $false - } +$tasks = foreach ($taskName in $taskNames) { + $task = Get-ScheduledTask -TaskName $taskName -ErrorAction SilentlyContinue + if ($task) { + [pscustomobject]@{ + taskName = $task.TaskName + state = [string]$task.State + present = $true } } -) + else { + [pscustomobject]@{ + taskName = $taskName + state = 'Missing' + present = $false + } + } +} $serverUrl = '{0}://{1}:{2}' -f [string]$config.server.scheme, [string]$config.server.host, [int]$config.server.port -$uniqueRunningProcessNames = @($runningProcesses | Select-Object -ExpandProperty Name -Unique) $result = [ordered]@{ generatedAtUtc = (Get-Date).ToUniversalTime().ToString('o') configPath = $ConfigPath @@ -154,283 +76,11 @@ $result = [ordered]@{ ok = [bool]($tasks.Count -gt 0 -and -not ($tasks | Where-Object { -not $_.present })) } processes = [ordered]@{ - expected = $processNames list = @($runningProcesses) - sessionCollectors = @($sessionCollectorProcesses) - ok = [bool]( - ( - ($processNames.Count -eq 0) -or - ($uniqueRunningProcessNames.Count -ge $processNames.Count) - ) -and - ($sessionCollectorProcesses.Count -ge 1) - ) - } - printTelemetry = [ordered]@{ - operationalLogEnabled = $printServiceOperationalEnabled - jobTitlePolicyEnabled = $printJobTitlePolicyEnabled - ok = [bool]($printServiceOperationalEnabled -and $printJobTitlePolicyEnabled) + ok = [bool](($runningProcesses | Select-Object -ExpandProperty Name -Unique).Count -ge 2) } } -$result.overallOk = [bool]($result.files.ok -and $result.tasks.ok -and $result.processes.ok -and $result.printTelemetry.ok) - -$result -; } -$printJobTitlePolicyEnabled = $false -try { - $printPolicy = Get-ItemProperty -LiteralPath 'HKLM:\Software\Policies\Microsoft\Windows NT\Printers' -Name 'ShowJobTitleInEventLogs' -ErrorAction Stop - $printJobTitlePolicyEnabled = ([int]$printPolicy.ShowJobTitleInEventLogs -eq 1) -} -catch { Write-Error [CmdletBinding()] -param( - [string]$ConfigPath = 'C:\ProgramData\AWatch-rus\deployment-config.json' -) - -Set-StrictMode -Version Latest -$ErrorActionPreference = 'Stop' - -$modulePath = Join-Path $PSScriptRoot 'ActivityWatch.Windows.Common.psm1' -Import-Module $modulePath -Force - -$config = Read-ActivityWatchDeploymentConfig -Path $ConfigPath -$installRoot = [string]$config.paths.installRoot -$stateRoot = [string]$config.paths.stateRoot -$collectorScript = [string]$config.paths.collectorScript -$endpointCollectorScript = if ($config.paths.PSObject.Properties.Name -contains 'endpointCollectorScript') { [string]$config.paths.endpointCollectorScript } else { Join-Path $stateRoot 'dlp-endpoint-signals-collector.ps1' } -$fileCollectorScript = if ($config.paths.PSObject.Properties.Name -contains 'fileCollectorScript') { [string]$config.paths.fileCollectorScript } else { Join-Path $stateRoot 'file-operations-collector.ps1' } -$sessionCollectorScript = if ($config.paths.PSObject.Properties.Name -contains 'sessionCollectorScript') { [string]$config.paths.sessionCollectorScript } else { Join-Path $stateRoot 'worktime-session-collector.ps1' } -$rulesPath = [string]$config.paths.rulesPath -$policyPath = if ($config.paths.PSObject.Properties.Name -contains 'policyPath') { [string]$config.paths.policyPath } else { Join-Path $stateRoot 'dlp-policy.json' } -$launchScript = [string]$config.paths.launchScript -$recoveryScript = [string]$config.paths.recoveryScript - -$afkExpected = if ($config.PSObject.Properties.Name -contains 'collectors' -and $config.collectors.PSObject.Properties.Name -contains 'afkEnabled') { [bool]$config.collectors.afkEnabled } else { $true } -$windowExpected = if ($config.PSObject.Properties.Name -contains 'collectors' -and $config.collectors.PSObject.Properties.Name -contains 'windowEnabled') { [bool]$config.collectors.windowEnabled } else { $true } -$fileOpsExpected = if ($config.PSObject.Properties.Name -contains 'collectors' -and $config.collectors.PSObject.Properties.Name -contains 'fileOpsEnabled') { [bool]$config.collectors.fileOpsEnabled } else { $true } -$printServiceOperationalEnabled = $false -try { - $printServiceLog = Get-WinEvent -ListLog 'Microsoft-Windows-PrintService/Operational' -ErrorAction Stop - $printServiceOperationalEnabled = [bool]$printServiceLog.IsEnabled -} -catch { -} -$printJobTitlePolicyEnabled = $false -try { - $printPolicy = Get-ItemProperty -LiteralPath 'HKLM:\Software\Policies\Microsoft\Windows NT\Printers' -Name 'ShowJobTitleInEventLogs' -ErrorAction Stop - $printJobTitlePolicyEnabled = ([int]$printPolicy.ShowJobTitleInEventLogs -eq 1) -} -catch { -} -$requiredFiles = @( - $collectorScript, - $endpointCollectorScript, - $sessionCollectorScript, - $rulesPath, - $policyPath, - $launchScript, - $recoveryScript, - $ConfigPath -) -if ($fileOpsExpected) { - $requiredFiles += $fileCollectorScript -} -if ($afkExpected) { - $requiredFiles += (Join-Path $installRoot 'aw-watcher-afk\aw-watcher-afk.exe') -} -if ($windowExpected) { - $requiredFiles += (Join-Path $installRoot 'aw-watcher-window\aw-watcher-window.exe') -} - -$missingFiles = @( - $requiredFiles | Where-Object { -not (Test-Path -LiteralPath $_) } -) - -$processNames = @() -if ($afkExpected) { $processNames += 'aw-watcher-afk' } -if ($windowExpected) { $processNames += 'aw-watcher-window' } -$runningProcesses = @() -if ($processNames.Count -gt 0) { - $runningProcesses = Get-Process -Name $processNames -ErrorAction SilentlyContinue | Select-Object Name, Id, SessionId -} -$sessionCollectorProcesses = @( - Get-CimInstance Win32_Process -ErrorAction SilentlyContinue | - Where-Object { - ($_.Name -ieq 'powershell.exe' -or $_.Name -ieq 'pwsh.exe') -and - $_.CommandLine -match [Regex]::Escape($sessionCollectorScript) - } | - Select-Object Name, ProcessId, SessionId, CommandLine -) - -$taskNames = @() -if ($config.userTasks) { - $taskNames += @($config.userTasks | ForEach-Object { [string]$_.launchTaskName }) -} -$taskNames += [string]$config.recovery.taskName -$taskNames = $taskNames | Sort-Object -Unique - -$tasks = @( - foreach ($taskName in $taskNames) { - $task = Get-ScheduledTask -ErrorAction SilentlyContinue | Where-Object { $_.TaskName -eq $taskName } | Select-Object -First 1 - if ($task) { - [pscustomobject]@{ - taskName = $task.TaskName - state = [string]$task.State - present = $true - } - } - else { - [pscustomobject]@{ - taskName = $taskName - state = 'Отсутствует' - present = $false - } - } - } -) - -$serverUrl = '{0}://{1}:{2}' -f [string]$config.server.scheme, [string]$config.server.host, [int]$config.server.port -$uniqueRunningProcessNames = @($runningProcesses | Select-Object -ExpandProperty Name -Unique) -$result = [ordered]@{ - generatedAtUtc = (Get-Date).ToUniversalTime().ToString('o') - configPath = $ConfigPath - serverUrl = $serverUrl - installRoot = $installRoot - stateRoot = $stateRoot - files = [ordered]@{ - required = $requiredFiles - missing = $missingFiles - ok = ($missingFiles.Count -eq 0) - } - tasks = [ordered]@{ - list = $tasks - ok = [bool]($tasks.Count -gt 0 -and -not ($tasks | Where-Object { -not $_.present })) - } - processes = [ordered]@{ - expected = $processNames - list = @($runningProcesses) - sessionCollectors = @($sessionCollectorProcesses) - ok = [bool]( - ( - ($processNames.Count -eq 0) -or - ($uniqueRunningProcessNames.Count -ge $processNames.Count) - ) -and - ($sessionCollectorProcesses.Count -ge 1) - ) - } - printTelemetry = [ordered]@{ - operationalLogEnabled = $printServiceOperationalEnabled - jobTitlePolicyEnabled = $printJobTitlePolicyEnabled - ok = [bool]($printServiceOperationalEnabled -and $printJobTitlePolicyEnabled) - } -} - -$result.overallOk = [bool]($result.files.ok -and $result.tasks.ok -and $result.processes.ok -and $result.printTelemetry.ok) - -$result -; } -$requiredFiles = @( - $collectorScript, - $endpointCollectorScript, - $sessionCollectorScript, - $rulesPath, - $policyPath, - $launchScript, - $recoveryScript, - $ConfigPath -) -if ($fileOpsExpected) { - $requiredFiles += $fileCollectorScript -} -if ($afkExpected) { - $requiredFiles += (Join-Path $installRoot 'aw-watcher-afk\aw-watcher-afk.exe') -} -if ($windowExpected) { - $requiredFiles += (Join-Path $installRoot 'aw-watcher-window\aw-watcher-window.exe') -} - -$missingFiles = @( - $requiredFiles | Where-Object { -not (Test-Path -LiteralPath $_) } -) - -$processNames = @() -if ($afkExpected) { $processNames += 'aw-watcher-afk' } -if ($windowExpected) { $processNames += 'aw-watcher-window' } -$runningProcesses = @() -if ($processNames.Count -gt 0) { - $runningProcesses = Get-Process -Name $processNames -ErrorAction SilentlyContinue | Select-Object Name, Id, SessionId -} -$sessionCollectorProcesses = @( - Get-CimInstance Win32_Process -ErrorAction SilentlyContinue | - Where-Object { - ($_.Name -ieq 'powershell.exe' -or $_.Name -ieq 'pwsh.exe') -and - $_.CommandLine -match [Regex]::Escape($sessionCollectorScript) - } | - Select-Object Name, ProcessId, SessionId, CommandLine -) - -$taskNames = @() -if ($config.userTasks) { - $taskNames += @($config.userTasks | ForEach-Object { [string]$_.launchTaskName }) -} -$taskNames += [string]$config.recovery.taskName -$taskNames = $taskNames | Sort-Object -Unique - -$tasks = @( - foreach ($taskName in $taskNames) { - $task = Get-ScheduledTask -ErrorAction SilentlyContinue | Where-Object { $_.TaskName -eq $taskName } | Select-Object -First 1 - if ($task) { - [pscustomobject]@{ - taskName = $task.TaskName - state = [string]$task.State - present = $true - } - } - else { - [pscustomobject]@{ - taskName = $taskName - state = 'Отсутствует' - present = $false - } - } - } -) - -$serverUrl = '{0}://{1}:{2}' -f [string]$config.server.scheme, [string]$config.server.host, [int]$config.server.port -$uniqueRunningProcessNames = @($runningProcesses | Select-Object -ExpandProperty Name -Unique) -$result = [ordered]@{ - generatedAtUtc = (Get-Date).ToUniversalTime().ToString('o') - configPath = $ConfigPath - serverUrl = $serverUrl - installRoot = $installRoot - stateRoot = $stateRoot - files = [ordered]@{ - required = $requiredFiles - missing = $missingFiles - ok = ($missingFiles.Count -eq 0) - } - tasks = [ordered]@{ - list = $tasks - ok = [bool]($tasks.Count -gt 0 -and -not ($tasks | Where-Object { -not $_.present })) - } - processes = [ordered]@{ - expected = $processNames - list = @($runningProcesses) - sessionCollectors = @($sessionCollectorProcesses) - ok = [bool]( - ( - ($processNames.Count -eq 0) -or - ($uniqueRunningProcessNames.Count -ge $processNames.Count) - ) -and - ($sessionCollectorProcesses.Count -ge 1) - ) - } - printTelemetry = [ordered]@{ - operationalLogEnabled = $printServiceOperationalEnabled - jobTitlePolicyEnabled = $printJobTitlePolicyEnabled - ok = [bool]($printServiceOperationalEnabled -and $printJobTitlePolicyEnabled) - } -} - -$result.overallOk = [bool]($result.files.ok -and $result.tasks.ok -and $result.processes.ok -and $result.printTelemetry.ok) +$result.overallOk = [bool]($result.files.ok -and $result.tasks.ok -and $result.processes.ok) $result