Sealed VMs were left with setup scripts on C:\, the config CD mounted,
and Windows unactivated. Rework the first-boot flow so a settled VM
carries no vmix artifacts:
- Activation moves off the throwaway bootstrap's boot 1 into the boot-2
finalize, which runs as the real account after its fresh SID/profile
exist -- MAS on that SID is what actually sticks. MAS is kept until
then, run once, and deleted.
- The static address is set once into the persistent store on the target
NIC (sealed images already OOBE on the real NIC), so no per-boot task
and no script survive on disk.
- Boot-2 finalize wipes every vmix-*, MAS_AIO.cmd, config and marker off
C:\ after use, retires the bootstrap account/profile, and self-deletes.
- The config CD is unmounted for good -- drop its letter and disable the
mount manager's auto-lettering (D: keeps its explicit assignment).
Non-configMedium generalize (the shared path) is unchanged.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0117qMyjpuXsjpVAcpJbFD8g