Make Windows Tentacle install path-agnostic and auto-elevate
Summary
Closes three operator-visible failures in the Squid-generated Windows install snippet, plus a CI repro fix:
-
Wrong binary name: server emitted
squid-tentacle.exe, but the .NET publish output isSquid.Tentacle.exe(perSquid.Tentacle.csprojRootNamespace). Every install hit "file not found" at register. -
Hardcoded install path: server emitted
'C:\Program Files\Squid Tentacle\…', breaking operators who override\$env:INSTALL_DIRor-InstallDir. -
No UAC auto-elevation:
install-tentacle.ps1errored out for non-admin shells instead of triggering UAC. -
Em-dash parse error: PowerShell 5.1 mis-decoded em-dashes under OEM codepage on
windows-latestrunners. Fixed + drift detector pinned.
Three-layer fix:
-
install-tentacle.ps1writes%ProgramData%\Squid\Tentacle\install-info.json(Schema=1) after extraction. -
install-tentacle.ps1auto-elevates viaStart-Process -Verb RunAs. Handles both file invocation andirm | iexpipe invocation. Skippable via-NoAutoElevatefor CI / SYSTEM-context. -
WindowsPowerShellScriptBuilderreads the discovery file in Step 2; uses\$tentaclethroughout Steps 3-4. Wraps register-call\$LASTEXITCODE = 403with a structured error namingMachineCreatepermission + the granting built-in roles (Environment Manager / Space Owner).
Tests:
- Unit (8 new): drift detectors for binary name, discovery-file path, em-dash absence in generated content, 4-step ordering, missing-discovery-file error, 403 hint contents, role-list accuracy.
-
E2E (9 new in resilience matrix): install-info.json schema, BinaryPath reflects
-InstallDir, idempotence stress (5×), corrupt-state recovery, paths-with-spaces.
Test plan
-
Unit: 5217/5217 pass locally -
Build: zero errors across all projects -
Windows CI: install-tentacle.ps1 + WindowsPowerShellScriptBuilder + 9 new resilience E2E tests pass on `windows-latest`