49 lines
3.1 KiB
Markdown
49 lines
3.1 KiB
Markdown
# Windows Lab Housekeeping
|
|
|
|
`tools/windows-housekeeping/Invoke-Housekeeping.ps1` is the idempotent lab guest
|
|
housekeeping script. It configures targeted policies, disables named scheduled
|
|
consumer/background tasks, stops named consumer nag processes, and removes the per-user
|
|
`Microsoft.MicrosoftOfficeHub` package when present. It does not uninstall generic
|
|
WebView/system components, change game files, networking, SSH, SMB, firewall, Defender
|
|
real-time protection, graphics/audio/runtime packages, or Windows servicing.
|
|
|
|
Run it as the existing administrative lab account over verified key-based SSH:
|
|
|
|
```powershell
|
|
powershell -ExecutionPolicy Bypass -File C:\SotsRe\Invoke-Housekeeping.ps1 -Mode Inspect
|
|
powershell -ExecutionPolicy Bypass -File C:\SotsRe\Invoke-Housekeeping.ps1 -Mode Apply
|
|
powershell -ExecutionPolicy Bypass -File C:\SotsRe\Invoke-Housekeeping.ps1 -Mode Verify
|
|
```
|
|
|
|
The script writes sanitized JSON to `C:\ProgramData\SotsRe\housekeeping-result.json`.
|
|
The orchestrator copies that result to `verify/results/housekeeping/` with the VM identity.
|
|
|
|
Protected-secret autologon is supported by `ConfigureAutologon`: stream the existing lab
|
|
account password on standard input from the approved private credential source. The script
|
|
first validates the credential with `LogonUser`, writes only the LSA `DefaultPassword`
|
|
secret, and then sets the non-secret Winlogon fields for user `re`. Do not place the
|
|
password on a command line, in a repository file, in logs, or in the plaintext Winlogon
|
|
`DefaultPassword` registry value. A free guest must be rebooted afterward to prove actual
|
|
console autologon; config-only verification is not a reboot proof.
|
|
|
|
Before each guest: verify identity/IP by MAC, inspect task/session/process activity, and
|
|
acquire a canonical `campaign/runtime/leases/vm<ID>.json` lease. Do not touch a guest with
|
|
an active game/test process, unknown console activity, or a lease held by another worker.
|
|
VM141's verified address in the current lab is `192.168.10.143`.
|
|
|
|
Latest routine completion results (2026-09-09, actor `housekeeping-completion`, model
|
|
`openai/gpt-5.5`): VM140/141/144/145/146 have compliant policy/task/startup cleanup and
|
|
protected autologon configuration in `verify/results/housekeeping/vm*-result.json`. VM141,
|
|
VM144, VM145, and VM146 were reboot-proven with `re` on the console plus key-based SSH
|
|
recovery. VM140 was not rebooted in that quantum because its existing active console was
|
|
preserved; its autologon config and SSH were verified, and remaining `msedgewebview2`
|
|
processes were recorded as generic WebView, not removed.
|
|
|
|
## Test preflight
|
|
|
|
After every reboot, and before capturing a new control/oracle, run `Apply` then `Verify` under
|
|
the VM lease and retain the sanitized result with the experiment. This is required by observed
|
|
behavior: Windows re-enabled the Defender scheduled scan and restarted OneDrive on VM146 after
|
|
login. The repeatable profile reapplies those controls; an earlier compliant JSON is not proof
|
|
of the current guest state. A failed preflight blocks the test rather than changing its baseline
|
|
mid-run. This profile preserves Defender real-time protection and Windows servicing.
|