Skip to content

Package HogWatch as a downloadable Windows exe - #4

Merged
MSabacreationslab merged 3 commits into
mainfrom
feature/windows-exe
Oct 4, 2026
Merged

MSabacreationslab merged 3 commits into
mainfrom
feature/windows-exe

Conversation

@MSabacreationslab

Copy link
Copy Markdown
Owner

What

HogWatch as a single downloadable HogWatch.exe, so someone without Python can run it.

The exe

  • build-exe.cmd builds dist\HogWatch.exe with PyInstaller: one file, no console window, the dashboard files and an icon packed in (9.3 MB).
  • Double-click (launch):
    • If HogWatch is already running, it just opens the dashboard.
    • Otherwise it starts a background copy as administrator (needed for per-program data), waits for it, opens the dashboard un-elevated, and exits.
    • If the admin prompt is refused, it runs anyway, without per-program detail.
  • Data lives in %LOCALAPPDATA%\HogWatch when packaged. --data-dir and --port (or HOGWATCH_DATA_DIR and HOGWATCH_PORT) override this. A copy on a non-default port gets its own ETW session, so it can't cut off the main one.

No terminal needed any more (dashboard)

  • Connect the eero: login, then the emailed or texted code, then a network choice if the account has several. Nothing is saved until a network is chosen. The token never comes back to the page.
  • HogWatch settings: a start-at-login switch (scheduled task with highest privileges, so no prompt at login), a Stop button, and the version and admin status.
  • The eero session token is now DPAPI-encrypted, like the email password. Plain tokens from older versions are upgraded on load.

Releases

  • tests.yml gains a package job that builds the exe and runs it on every PR.
  • release.yml: pushing tag vX.Y.Z (it must match hogwatch.__version__) runs the tests, builds and runs the exe on a clean runner, and publishes it with a SHA-256 checksum and install notes.

Fix: the hidden attribute lost to display: grid on forms; [hidden] { display: none !important }.

Testing

  • 83 tests pass locally. 20 are new in tests/test_packaging.py: the data folder when packaged, option parsing, the encrypted eero session and upgrade from plain text, the autostart command and quoting, the dashboard sign-in flow against a fake eero, the header requirement, the autostart switch, and all four launcher paths.
  • The built exe was run for real on Windows 11:
    • un-elevated on a spare port: dashboard, API and data folder all correct
    • as a double-click: the admin prompt appeared, the background copy started elevated with per-program tracking on, the dashboard opened, and the launcher exited
    • stopped from the dashboard's Stop button
    • a second HogWatch running beside it was unaffected
  • scripts/smoke_test_exe.ps1 passes locally.
  • Not tested: a real eero sign-in through the new form (the flow is tested against a stand-in), and first run on a PC that has never had HogWatch.

Known limitation

The exe is not code-signed, so Windows SmartScreen shows "unknown publisher" on first run (More info → Run anyway). The README and release notes say so.

🤖 Generated with Claude Code

MSabacreationslab and others added 3 commits October 4, 2026 13:59
- hogwatch_app.py + build-exe.cmd build dist\HogWatch.exe with PyInstaller
  (one file, no console, dashboard files and an icon packed in).
- Double-clicking it (launch): open the dashboard if already running; otherwise
  start a background copy as administrator, wait for it, open the dashboard
  un-elevated, and exit. A refused admin prompt falls back to running without
  per-program detail.
- Packaged data lives in %LOCALAPPDATA%\HogWatch; --data-dir/--port (or
  HOGWATCH_DATA_DIR/HOGWATCH_PORT) override, and a copy on another port gets
  its own ETW session so it can't cut off the main one.
- Dashboard: sign in to eero (login, code, network choice), start-at-login
  switch, Stop button, version. No terminal needed.
- The eero session token is now DPAPI-encrypted; plain tokens from older
  versions are upgraded on load.
- stop command; browser is opened via explorer.exe so it never runs elevated.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The package job builds HogWatch.exe and runs it (dashboard, API, data folder).
Pushing a tag vX.Y.Z that matches hogwatch.__version__ runs the tests, builds
and runs the exe on a clean runner, and publishes it with a SHA-256 checksum.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@MSabacreationslab
MSabacreationslab merged commit c33422b into main Oct 4, 2026
2 checks passed
@MSabacreationslab
MSabacreationslab deleted the feature/windows-exe branch October 4, 2026 18:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant