改造开始前的完整状态,作为可回退的基点。此提交之后:Pester 175 项、零依赖套件 101 项全绿;PowerShell 5.1 尚不可用(源文件无 BOM)。 包含此前未提交的在制品:安全描述符套件、Hyper-V 实验环境(tools/lab)、agent 约定(AGENTS.md 与 docs/agents)。 .gitignore 增加 *.key / *.pfx:BackupConfig.psd1 的 PasswordFile 此前默认指向仓库内的 baknret.key,一次 git add -A 就会把口令提交进版本库。默认值在后续提交中改为空。
126 lines
5.1 KiB
XML
126 lines
5.1 KiB
XML
<?xml version="1.0" encoding="utf-8"?>
|
||
<!--
|
||
BakNRet 隔离测试 VM 的无人值守应答文件(离线部署路径)。
|
||
|
||
Windows 用 DISM 展开到 VHDX 之后,本文件被放到 C:\Windows\Panther\unattend.xml,
|
||
首次启动时由 Windows 在 specialize 与 oobeSystem 两个阶段读取。
|
||
|
||
设计要点:
|
||
* 不启用已废弃的 SkipMachineOOBE / SkipUserOOBE —— 在 Windows 11 25H2 上它们会让
|
||
OOBE 卡住;这里改用 OOBE 隐藏项 + BypassNRO + 明确的本地账户;
|
||
* 只创建一个本地管理员 lab,避免 OOBE 索要微软账户;
|
||
* AutoLogon 三次,用来跑 FirstLogonCommands 里的供给脚本;
|
||
* 口令占位符 __LABPASSWORD__ 由 tools\lab\New-BakNRetLab.ps1 在注入前替换成随机口令,
|
||
口令只留在宿主机 D:\VMs\BakNRet-Lab\state\credentials.json,不进版本库。
|
||
-->
|
||
<unattend xmlns="urn:schemas-microsoft-com:unattend">
|
||
|
||
<settings pass="specialize">
|
||
|
||
<component name="Microsoft-Windows-Shell-Setup"
|
||
processorArchitecture="amd64"
|
||
publicKeyToken="31bf3856ad364e35"
|
||
language="neutral"
|
||
versionScope="nonSxS"
|
||
xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State"
|
||
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
|
||
<ComputerName>BAKNRET-LAB</ComputerName>
|
||
<TimeZone>China Standard Time</TimeZone>
|
||
<RegisteredOwner>BakNRet Lab</RegisteredOwner>
|
||
<RegisteredOrganization>BakNRet Lab</RegisteredOrganization>
|
||
</component>
|
||
|
||
<component name="Microsoft-Windows-Deployment"
|
||
processorArchitecture="amd64"
|
||
publicKeyToken="31bf3856ad364e35"
|
||
language="neutral"
|
||
versionScope="nonSxS"
|
||
xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State"
|
||
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
|
||
<RunSynchronous>
|
||
<RunSynchronousCommand wcm:action="add">
|
||
<Order>1</Order>
|
||
<Description>跳过 OOBE 的联网 / 微软账户强制</Description>
|
||
<Path>reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v BypassNRO /t REG_DWORD /d 1 /f</Path>
|
||
</RunSynchronousCommand>
|
||
<RunSynchronousCommand wcm:action="add">
|
||
<Order>2</Order>
|
||
<Description>关掉“让我们完成设备设置”一类打扰</Description>
|
||
<Path>reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\UserProfileEngagement" /v ScoobeSystemSettingEnabled /t REG_DWORD /d 0 /f</Path>
|
||
</RunSynchronousCommand>
|
||
</RunSynchronous>
|
||
</component>
|
||
|
||
</settings>
|
||
|
||
<settings pass="oobeSystem">
|
||
|
||
<component name="Microsoft-Windows-International-Core"
|
||
processorArchitecture="amd64"
|
||
publicKeyToken="31bf3856ad364e35"
|
||
language="neutral"
|
||
versionScope="nonSxS"
|
||
xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State"
|
||
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
|
||
<InputLocale>zh-CN</InputLocale>
|
||
<SystemLocale>zh-CN</SystemLocale>
|
||
<UILanguage>zh-CN</UILanguage>
|
||
<UserLocale>zh-CN</UserLocale>
|
||
</component>
|
||
|
||
<component name="Microsoft-Windows-Shell-Setup"
|
||
processorArchitecture="amd64"
|
||
publicKeyToken="31bf3856ad364e35"
|
||
language="neutral"
|
||
versionScope="nonSxS"
|
||
xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State"
|
||
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
|
||
|
||
<OOBE>
|
||
<HideEULAPage>true</HideEULAPage>
|
||
<HideOEMRegistrationScreen>true</HideOEMRegistrationScreen>
|
||
<HideOnlineAccountScreens>true</HideOnlineAccountScreens>
|
||
<HideWirelessSetupInOOBE>true</HideWirelessSetupInOOBE>
|
||
<NetworkLocation>Work</NetworkLocation>
|
||
<ProtectYourPC>3</ProtectYourPC>
|
||
</OOBE>
|
||
|
||
<UserAccounts>
|
||
<LocalAccounts>
|
||
<LocalAccount wcm:action="add">
|
||
<Name>lab</Name>
|
||
<DisplayName>Lab</DisplayName>
|
||
<Description>BakNRet 隔离测试账户</Description>
|
||
<Group>Administrators</Group>
|
||
<Password>
|
||
<Value>__LABPASSWORD__</Value>
|
||
<PlainText>true</PlainText>
|
||
</Password>
|
||
</LocalAccount>
|
||
</LocalAccounts>
|
||
</UserAccounts>
|
||
|
||
<AutoLogon>
|
||
<Username>lab</Username>
|
||
<Enabled>true</Enabled>
|
||
<LogonCount>3</LogonCount>
|
||
<Password>
|
||
<Value>__LABPASSWORD__</Value>
|
||
<PlainText>true</PlainText>
|
||
</Password>
|
||
</AutoLogon>
|
||
|
||
<FirstLogonCommands>
|
||
<SynchronousCommand wcm:action="add">
|
||
<Order>1</Order>
|
||
<Description>BakNRet lab 供给脚本(把 VM 变成可跑全链路测试的真机状态)</Description>
|
||
<CommandLine>powershell.exe -NoProfile -ExecutionPolicy Bypass -File C:\BakNRet-Lab\payload\provision.ps1</CommandLine>
|
||
</SynchronousCommand>
|
||
</FirstLogonCommands>
|
||
|
||
<TimeZone>China Standard Time</TimeZone>
|
||
</component>
|
||
|
||
</settings>
|
||
|
||
</unattend> |