Fix backward compatibility bug with Windows MSI END_USER_EMAIL (#20116)
#19219 Fix unreleased backward compatibility bug with Windows MSI END_USER_EMAIL # Checklist for submitter <!-- Note that API documentation changes are now addressed by the product design team. --> - [x] Manual QA for all new/changed functionality
This commit is contained in:
@@ -117,6 +117,8 @@ type Options struct {
|
||||
LocalWixDir string
|
||||
// HostIdentifier is the host identifier to use in osquery.
|
||||
HostIdentifier string
|
||||
// EnableHostIdentifierProperty is a boolean indicating whether to enable END_USER_EMAIL property in Windows MSI package.
|
||||
EnableEndUserEmailProperty bool
|
||||
// EndUserEmail is the email address of the end user that uses the host on
|
||||
// which the agent is going to be installed.
|
||||
EndUserEmail string
|
||||
|
||||
@@ -24,6 +24,7 @@ import (
|
||||
"github.com/fleetdm/fleet/v4/pkg/secure"
|
||||
"github.com/josephspurrier/goversioninfo"
|
||||
"github.com/rs/zerolog/log"
|
||||
"golang.org/x/mod/semver"
|
||||
)
|
||||
|
||||
const wixDownload = "https://github.com/wixtoolset/wix3/releases/download/wix3112rtm/wix311-binaries.zip"
|
||||
@@ -87,6 +88,15 @@ func BuildMSI(opt Options) (string, error) {
|
||||
opt.Version = updatesData.OrbitVersion
|
||||
}
|
||||
|
||||
orbitVersion := updatesData.OrbitVersion
|
||||
if !strings.HasPrefix(orbitVersion, "v") {
|
||||
orbitVersion = "v" + orbitVersion
|
||||
}
|
||||
// v1.28.0 introduced configurable END_USER_EMAIL property for MSI package: https://github.com/fleetdm/fleet/issues/19219
|
||||
if semver.Compare(orbitVersion, "v1.28.0") >= 0 {
|
||||
opt.EnableEndUserEmailProperty = true
|
||||
}
|
||||
|
||||
// Write files
|
||||
|
||||
if err := writeSecret(opt, orbitRoot); err != nil {
|
||||
|
||||
@@ -58,7 +58,13 @@ var windowsWixTemplate = template.Must(template.New("").Option("missingkey=error
|
||||
<Property Id="FLEET_SECRET" Value="dummy"/>
|
||||
<Property Id="ENABLE_SCRIPTS" Value="{{ if .EnableScripts }}True{{ else }}False{{ end }}"/>
|
||||
<Property Id="FLEET_DESKTOP" Value="{{ if .Desktop }}True{{ else }}False{{ end }}"/>
|
||||
<Property Id="END_USER_EMAIL" Value="{{ if .EndUserEmail }}{{ .EndUserEmail }}{{ else }}dummy{{end}}"/>
|
||||
{{ $endUserEmailArg := "" }}
|
||||
{{ if .EnableEndUserEmailProperty }}
|
||||
<Property Id="END_USER_EMAIL" Value="{{ if .EndUserEmail }}{{ .EndUserEmail }}{{ else }}dummy{{end}}"/>
|
||||
{{ $endUserEmailArg = " --end-user-email=\"[END_USER_EMAIL]\"" }}
|
||||
{{ else if .EndUserEmail }}
|
||||
{{ $endUserEmailArg = printf " --end-user-email \"%s\"" .EndUserEmail }}
|
||||
{{ end }}
|
||||
|
||||
<MediaTemplate EmbedCab="yes" />
|
||||
|
||||
@@ -102,7 +108,7 @@ var windowsWixTemplate = template.Must(template.New("").Option("missingkey=error
|
||||
Start="auto"
|
||||
Type="ownProcess"
|
||||
Description="This service runs Fleet's osquery runtime and autoupdater (Orbit)."
|
||||
Arguments='--root-dir "[ORBITROOT]." --log-file "[System64Folder]config\systemprofile\AppData\Local\FleetDM\Orbit\Logs\orbit-osquery.log" --fleet-url "[FLEET_URL]"{{ if .FleetCertificate }} --fleet-certificate "[ORBITROOT]fleet.pem"{{ end }}{{ if .EnrollSecret }} --enroll-secret-path "[ORBITROOT]secret.txt"{{ end }}{{if .Insecure }} --insecure{{ end }}{{ if .Debug }} --debug{{ end }}{{ if .UpdateURL }} --update-url "{{ .UpdateURL }}"{{ end }}{{ if .UpdateTLSServerCertificate }} --update-tls-certificate "[ORBITROOT]update.pem"{{ end }}{{ if .DisableUpdates }} --disable-updates{{ end }} --fleet-desktop="[FLEET_DESKTOP]" --desktop-channel {{ .DesktopChannel }}{{ if .FleetDesktopAlternativeBrowserHost }} --fleet-desktop-alternative-browser-host {{ .FleetDesktopAlternativeBrowserHost }}{{ end }} --orbit-channel "{{ .OrbitChannel }}" --osqueryd-channel "{{ .OsquerydChannel }}" --enable-scripts="[ENABLE_SCRIPTS]" {{ if and (ne .HostIdentifier "") (ne .HostIdentifier "uuid") }}--host-identifier={{ .HostIdentifier }}{{ end }} --end-user-email "[END_USER_EMAIL]"{{ if .OsqueryDB }} --osquery-db="{{ .OsqueryDB }}"{{ end }}'
|
||||
Arguments='--root-dir "[ORBITROOT]." --log-file "[System64Folder]config\systemprofile\AppData\Local\FleetDM\Orbit\Logs\orbit-osquery.log" --fleet-url "[FLEET_URL]"{{ if .FleetCertificate }} --fleet-certificate "[ORBITROOT]fleet.pem"{{ end }}{{ if .EnrollSecret }} --enroll-secret-path "[ORBITROOT]secret.txt"{{ end }}{{if .Insecure }} --insecure{{ end }}{{ if .Debug }} --debug{{ end }}{{ if .UpdateURL }} --update-url "{{ .UpdateURL }}"{{ end }}{{ if .UpdateTLSServerCertificate }} --update-tls-certificate "[ORBITROOT]update.pem"{{ end }}{{ if .DisableUpdates }} --disable-updates{{ end }} --fleet-desktop="[FLEET_DESKTOP]" --desktop-channel {{ .DesktopChannel }}{{ if .FleetDesktopAlternativeBrowserHost }} --fleet-desktop-alternative-browser-host {{ .FleetDesktopAlternativeBrowserHost }}{{ end }} --orbit-channel "{{ .OrbitChannel }}" --osqueryd-channel "{{ .OsquerydChannel }}" --enable-scripts="[ENABLE_SCRIPTS]" {{ if and (ne .HostIdentifier "") (ne .HostIdentifier "uuid") }}--host-identifier={{ .HostIdentifier }}{{ end }}{{ $endUserEmailArg }}{{ if .OsqueryDB }} --osquery-db="{{ .OsqueryDB }}"{{ end }}'
|
||||
>
|
||||
<util:ServiceConfig
|
||||
FirstFailureActionType="restart"
|
||||
|
||||
Reference in New Issue
Block a user