summaryrefslogtreecommitdiffstats
path: root/packaging/win/README.md
diff options
context:
space:
mode:
Diffstat (limited to 'packaging/win/README.md')
-rw-r--r--packaging/win/README.md23
1 files changed, 15 insertions, 8 deletions
diff --git a/packaging/win/README.md b/packaging/win/README.md
index 8c29785..7bd7f67 100644
--- a/packaging/win/README.md
+++ b/packaging/win/README.md
@@ -11,6 +11,7 @@ Linux). `meshbay-common` rides along inside the node runtime.
├─ MeshBay.exe Electron client
├─ resources\
│ ├─ app.asar src/ + ui/ (the interface ships in the package)
+│ ├─ firewall.ps1 adds/removes the two inbound rules (see below)
│ └─ node-runtime\
│ ├─ meshbay-node.exe frozen daemon (PyInstaller onedir)
│ ├─ _internal\ … its Python + deps (aiortc, av, aioquic, …)
@@ -88,14 +89,20 @@ publish their host candidate as an unresolvable `<uuid>.local` mDNS name that
`aioice` discards — the browser always dials the node, never the reverse. So the
node has to accept unsolicited inbound UDP from its peers.
-**Windows Defender Firewall.** On the daemon's first run Windows pops a prompt
-for `meshbay-node.exe`. Tick **both Private and Public** — a libvirt/VM adapter,
-and sometimes a plain Ethernet one, registers as Public, and a Private-only rule
-then silently drops every peer. The installer cannot pre-create this rule (it is
-per-user and never elevates); the prompt is the mechanism. If you dismissed it,
-add the rule by hand: *Windows Defender Firewall → Advanced → Inbound Rules →
-New Rule → Program →* the bundled `…\resources\node-runtime\meshbay-node.exe` *→
-Allow → all profiles*.
+**Windows Defender Firewall.** The setup wizard offers to add the inbound rules
+for `MeshBay.exe` and `meshbay-node.exe` in one step — it needs one admin
+confirmation (`build/installer.nsh` runs `firewall.ps1` via NSIS `ExecShellWait
+"runas"`; the per-user install itself never elevates). Say yes and both
+prompts you'd otherwise hit mid-use are gone; say no, or the UAC prompt is
+dismissed, and Windows falls back to its own **"Allow access"** dialog the
+first time each process binds a socket — tick **both Private and Public** then
+(a libvirt/VM adapter, and sometimes a plain Ethernet one, registers as
+Public; a Private-only rule silently drops every peer). Missed both? Add it by
+hand: *Windows Defender Firewall → Advanced → Inbound Rules → New Rule →
+Program →* the bundled `…\resources\node-runtime\meshbay-node.exe` *→ Allow →
+all profiles*. `firewall.ps1` is idempotent and re-runnable
+(`powershell -File resources\firewall.ps1 add`, elevated); it logs to
+`%TEMP%\meshbay-firewall.log`.
**A flat LAN needs nothing else.** The node offers a routable `192.168.x.y` host
candidate and browsers on the same subnet connect straight to it — same as the