5090_WALKTHROUGH_SCRIPT.md

pipelines/5090_WALKTHROUGH_SCRIPT.md

THE ALLY-X WALK-THROUGH SCRIPT — the 5090 arrival evening

Status: ACTIVE (director-landed 2026-07-28; fresh-context critic GO_WITH_FIXES, all fixes applied — 7 MAJOR / 6 MINOR / 3 NOTE; 25/25 runbook citations spot-verified by the critic). Authority: docs/5090_SETUP_RUNBOOK.md — the D-19 ruling block, the SCHEDULE

REVISION block, THE HANDS-ON CHECKLIST, THE WALK-THROUGH MODE — plus docs/PRE_5090_BUILD_PLAN.md ledger

2026-07-28x. Every step cites the stage or J-item it implements. Lands with a docs/DOC_MAP.md row.

What this is: the guided sequence for the evening the box arrives, possibly Thursday 2026-07-30, worst case

assumed — the whole hands-on window is that one evening, ending before a ~2 AM airport departure. Josh's hands at

the box, this script narrating from the ROG Ally X. It ends where the on-box Claude Code session takes over

Stages 0-8. Hands-on budget about two and a quarter hours; nothing here waits on a download.

THE EIGHT NON-NEGOTIABLES (Josh's own list — everything else is remote-fixable later)

1. BIOS restore-power-on-AC — steps 30-32.

2. Auto-login, never-sleep, power button does nothing — steps 24-25, 56.

3. Tailscale enrolled (J10) — step 39.

4. RustDesk installed, unattended access plus permanent password — steps 41-43.

5. Both layers verified from the phone on cellular — steps 44 AND 45 (44 proves RustDesk, 45 proves Tailscale).

6. UPS USB cable seated plus the agent installed — steps 14, 27.

7. Repo clones and the big pulls STARTED — steps 51-54b, run AFTER item 8 (see the §7 ORDER NOTE).

8. A cold-reboot test proving the machine comes back reachable untouched — steps 58-61.

Every other step is marked SKIPPABLE. A skipped SKIPPABLE step costs nothing — the on-box session fixes it over

RustDesk. A missed non-negotiable costs the trip.

IF THE EVENING IS SHORT (box lands late, or a T-block eats an hour): THE 45-MINUTE PATH is steps 9-14, 18-25,

27, 30-31, 38-44, 45, 56, 58, 60, 61 — power chain, never-sleep, UPS cable + agent, restore-on-AC, both remote

layers off-LAN, auto-logon, cold-reboot proof. It drops the BIOS iGPU move (33/36), Windows Update, and all of

§7. THE STOP-CLOCK: if it is past 00:30 and section 8 has not started, skip section 7 entirely and go straight

to step 56. Item 8 is the gate; item 7 is bandwidth you can start over RustDesk from the airport.

OS STATE — what the runbook assumes, verified

The runbook assumes an integrator build with Windows already installed: J1 is "Windows OOBE" (the first-run

wizard, not an install), 0.1 says the build is validated as delivered, 2.3 refers to Puget's factory image, and

no step anywhere installs an OS, enters a product key, or uses driver media. That matches the machine as ordered.

Two variances to watch: D-16 (a different boot or partition arrangement shipped — re-map, never re-image), and a

box that boots straight to a desktop because the integrator completed OOBE, in which case an account already

exists and its password is in the Puget paperwork, not in your head. Never guess it. CONFIRMED 2026-07-28 from

Puget's own QC checklist: Windows 11 Pro, OOBE verified as the ship state (the boots-to-desktop variance should

NOT occur), Secure Boot enabled, restore media created. Courtesy installs already on the box: Parsec (a bonus

remote-desktop FALLBACK — Tailscale + RustDesk stay the ruled stack; Parsec sign-in is optional, not tonight's

problem), NVIDIA App, Chrome.

1 — BEFORE THE BOX ARRIVES (10 minutes, at work or lunch)

1. Puget POSTS the benchmark results + temperature logs when the box ships (confirmed from the build checklist

Josh posted 2026-07-28 — Phase 1 memory testing + Phase 2 stress test are DONE by Puget). Find the link in

the ship email or account page; the on-box session captures it into the setup artifacts as W0's thermals

baseline. Nothing to request. [D-1 evidence rider] Expect: you know where the posted results live. SKIPPABLE.

2. Install Tailscale on the phone and sign in. [J10] Expect: an empty or phone-only device list. Prerequisite for

item 3.

3. Install RustDesk on the phone; configure nothing. Expect: the app opens to an ID field. Prerequisite for

item 5.

4. Confirm you can sign in to Claude Code tonight and that the three Max x20 subscriptions are live. [J7, 4.3]

Expect: you know the account and can reach its second factor.

5. Confirm your GitHub sign-in method (browser flow or gh auth login) and your Epic account. [J5, J6] Both are

needed tonight — checklist item 7 cannot start without J5.

6. Write down the house Wi-Fi password, and check whether a spare ethernet cable reaches the router.

7. If the UPS came in a separate, earlier delivery, unbox it and plug it into the wall now — it wants hours.

[0.2] IMPORTANT: the runbook records the UPS as arriving with the machine, so this is probably impossible. If

it lands in the same delivery it only starts charging at step 10, and every charge-dependent step (0.5

calibration, the 0.6 and 0.7 pull-the-plug tests) CANNOT complete tonight. None is on the eight-item list —

do not let a discharged UPS hold up the evening.

8. Clear the desk, and confirm the tower's wall circuit is not shared with a heater, microwave, or window AC.

[0.4, D-13] SKIPPABLE; it becomes non-optional if the breaker ever trips under load.

8b. Confirm the ROG Ally X is on the house Wi-Fi and will stay awake — step 54b copies a 9GB file off it.

[CONTINUO ADDITIONS] Expect: the Ally is on the LAN with sleep deferred.

2 — THE PHYSICAL CHAIN (25-35 minutes)

9. Before powering anything, photograph the packing slip and the as-built spec sheet, then look for shipping

damage, a shifted GPU, loose screws, or bent pins. [0.1] Expect: nothing loose. Two minutes, and the only

RMA-window check there is — anything found stops the evening and becomes a Puget call (tier-(c) abort rule).

10. Place the UPS first with front and rear clearance, plug it into the wall, switch it on. [0.2] Expect: panel

lit, reading on-line, not on-battery.

11. Read the UPS's own rear label and identify which bank is battery-plus-surge and which is surge-only. [0.3 —

the label wins over any document, this one included.] Expect: you can say out loud which bank is which.

12. Into the battery bank and nothing else: the tower's single PSU cable, the primary monitor, the router or

modem or switch. [0.3, D-11c] Expect: three cords in the battery bank.

13. Into the surge-only bank: second and third monitors, every peripheral. They are meant to die on an outage

rather than burn shutdown runtime. [D-11c ruling rider]

14. Connect the USB data cable from the UPS to the tower. [0.5] NON-NEGOTIABLE — checklist item 6, and the only

half of it that is physically impossible after you leave.

15. Leave the primary monitor's cable in the 5090's output for now. It moves at step 36, after the BIOS trip,

never before. [2.1 — the ordering exists so a wrong BIOS setting cannot leave you headless.]

16. Network: prefer a wired ethernet run from the tower to the battery-backed router. The runbook is silent on

wired versus wireless — the only related ruling is router-on-battery at 0.3 — and wired removes a failure

class from the remote path. If no cable reaches, Wi-Fi is fine; step 61 proves it reconnects unattended.

17. Keyboard and mouse into the tower. Nothing with a motor or a heater goes near the UPS. [0.3]

3 — FIRST BOOT AND WINDOWS FIRST RUN (20-30 minutes)

18. Power the tower on. Expect: the vendor splash, then the Windows first-run wizard or an existing desktop.

Neither appears — go to T1.

19. If the wizard appears, work through region and keyboard and let it connect to the network. Expect: a

connected indicator before the account screen.

20. Choose a LOCAL account, not a Microsoft account. [J1] A Microsoft-account sign-in is what can silently

auto-enable device encryption (1.9), and an encryption prompt at an unattended boot ends the window as surely

as no power. With a Microsoft account, escrowing the recovery key (J3) becomes mandatory tonight.

21. Set a password you can type from memory at 1 AM. You need it again at step 56.

22. Decline every optional offer — personalization, advertising ID, location, activity history, cloud backup, any

bundled subscription pitch. Expect: a bare desktop.

23. Rename the machine to something you will recognize in a Tailscale and RustDesk device list: Settings, System,

About, Rename this PC. Expect: a reboot prompt — accept it. This is NOT the BIOS trip; let it come back to the desktop and continue

at step 24.

24. Open PowerShell as administrator and run these four, one at a time:

powercfg /change standby-timeout-ac 0

powercfg /change hibernate-timeout-ac 0

powercfg /change monitor-timeout-ac 15

powercfg /hibernate off

[1.2] Expect: no output from any of them — silence is success. The last also kills fast startup, which is

what makes "clean shutdown" mean what it says. NON-NEGOTIABLE (item 2).

25. Make the power button do nothing:

powercfg /setacvalueindex scheme_current sub_buttons pbuttonaction 0

powercfg /setactive scheme_current

Expect: no output. NON-NEGOTIABLE (item 2). Josh's checklist also says "lid" — a tower has none, so the power

button is the whole of it.

26. Stop USB selective suspend from dropping the UPS data link:

powercfg /setacvalueindex scheme_current 2a737441-1930-4402-8d77-b2bebba308a3 48e6b7a6-50f5-4782-9a4b-a9e56e0d0e0e 0

powercfg /setactive scheme_current

[1.2] Expect: no output. SKIPPABLE — remote-drivable.

27. Install the CyberPower PowerPanel agent, in the edition the PR1500RTXL2UC's own manual pairs it with

(Business expected; the two editions are different products). No cloud enrollment tonight — J9 stays

untouched. [0.5] Expect: the agent names the unit by model, not just "a UPS". NON-NEGOTIABLE (item 6).

Configure nothing else — calibration and the shutdown trigger need a full charge and belong to the on-box

session.

28. Start Windows Update and walk away. [1.1] Expect: downloading. SKIPPABLE — the on-box session drives it to

quiescence. Do not wait, and do not let it reboot while you are in BIOS.

4 — THE BIOS PASS (10-15 minutes, exactly one trip)

29. In an admin PowerShell run manage-bde -status C:. Expect: a Protection Status line. Protection On means

capture and escrow the recovery key BEFORE changing any BIOS setting — a firmware change can force a recovery

prompt at next boot. [J3, 1.9, D-17] The key is a credential: somewhere Josh controls, never into a session.

30. Reboot and press the BIOS key at the splash (Del or F2; the Puget paperwork names it). Expect: BIOS.

31. Set Restore on AC Power Loss — also labelled AC Back or After Power Failure — to Power On. [2.1 step 3]

Expect: it reads Power On. NON-NEGOTIABLE (item 1), and link one of the auto-restart chain 0.7 verifies.

32. Look for a scheduled power-on or RTC wake item, note where it lives, leave it disabled. [item 1's

parenthetical] The runbook prescribes no value — record the location for the on-box session. Expect: you

can name the menu path.

33. Enable the integrated GPU and set initial display output to iGPU, or Auto if that is the only option. [2.1

step 2, 2.2] HANDS-ONLY and not on Josh's eight: a BIOS change plus a cable move, impossible from abroad. The

29-of-32GB VRAM fit depends on it, and the runbook expects the machine to arrive with the rule violated.

34. Confirm the memory is on its rated EXPO or XMP profile as shipped, and change nothing. Note the BIOS version.

[2.1 step 4] SKIPPABLE to record, never to change.

35. Save, exit, and shut the machine fully down. Expect: the machine powers off.

36. With the machine off, move the primary monitor cable from the 5090 to the motherboard port, then power on.

Expect: a picture. If there is none, put the cable back on the 5090, re-enter BIOS, set initial display back

to PCIe, save, and abandon the iGPU rule tonight — the on-box session re-plans it. (This resolves an ambiguity

in 2.1 steps 6-7, which ask you to confirm the motherboard port while the monitors are still on the card.)

37. Leave the second and third monitors where they are — surge-only, load-bearing for nothing. SKIPPABLE.

5 — THE REMOTE STACK (20-30 minutes — the heart of the evening)

38. Set the network profile to Private: Settings, Network, the active connection, Private. [6F.1] Expect: it

reads Private. A Public profile prompts far more, and an unacknowledged firewall dialog is a stall class.

39. Install Tailscale on the PC and sign in with the same account as the phone. [J10, D-19] Expect: the PC

appears in the phone's device list with a 100.x.y.z address. Write that address down. NON-NEGOTIABLE (item 3).

40. If Tailscale offers to disable key expiry for this machine, do it. Not a runbook instruction — an operator

recommendation: an expired node key is a dead remote path discovered from abroad. SKIPPABLE.

41. Install RustDesk on the PC. If the build offers an Install button that converts it to a service, take it —

the service is what makes it survive a reboot and a logout. [D-19 addendum] Expect: a nine-digit ID.

42. In RustDesk's security settings, set a permanent password and enable unattended access. [D-19 addendum]

Expect: the security page shows unattended access enabled with a permanent password set, and RustDesk reports

its service running. Persistence across a reboot is proven at step 61 — do not try to check it here.

NON-NEGOTIABLE (item 4).

43. Write the RustDesk ID and permanent password somewhere Josh controls. They are credentials: never pasted into

a session. [JOSH AT THE KEYBOARD block] NON-NEGOTIABLE.

44. THE OFF-LAN TEST. Turn Wi-Fi OFF on the phone and confirm cellular data. Open Tailscale on the phone, confirm

connected. Open RustDesk, enter the PC's ID and the permanent password. Expect: the desktop appears and the

mouse moves when you drag. [item 5] NON-NEGOTIABLE — a remote fault must never be found from abroad.

45. Repeat using the PC's 100.x Tailscale address instead of the RustDesk ID. Expect: the same desktop. This

proves the path without RustDesk's public rendezvous — it is the ONLY step that proves the Tailscale layer

itself carries traffic off-LAN. NON-NEGOTIABLE: step 44 alone proves RustDesk, not both layers.

45b. Parsec ships preinstalled (Puget courtesy install) — sign in once and enable hosting. [PUGET AS-BUILT

block] Expect: the machine appears in your Parsec account's computer list. SKIPPABLE (~3 min) — a THIRD

independent remote path across two vendors plus one self-routed, and later the preferred high-fidelity

screen for UE visual work. It replaces NEITHER ruled layer: Tailscale is the network (file transfer,

status reads, no desktop needed) and RustDesk-over-Tailscale is the desktop path with no vendor cloud in

it. Parsec's account/relay infrastructure is exactly the single-vendor dependency the two-layer ruling

exists to avoid.

46. Black screen instead of a desktop — go to T4.

6 — CLAUDE CODE ON THE BOX (10 minutes — the handover)

47. Install Claude Code on the new PC and sign in. [J7, 4.3] Expect: the CLI runs, reports a signed-in account,

and the three Max x20 subscriptions chain. Install via the official Windows installer or npm, whichever the account's docs currently name — if the first

path stalls, use the other rather than debugging it tonight. NON-NEGOTIABLE — checklist item 7 routes

through it (item 8 does not; the cold-reboot proof needs only the phone).

48. Note the full path of the installed claude.exe — the on-box session needs it for the

CLAUDE_CODE_EXECUTABLE user variable NeoStack's bridge depends on. [4.2]

49. Create C:\dev and start a Claude Code session in it. Expect: the session responds.

50. Hand over, in these words or close: do NOT start anything yet — we reboot first, and a reboot restarts a

clone from zero. When I reconnect after the reboot, clone both repos —

git clone https://github.com/milkman3790/HumanityForgotten.git C:\dev\humanity-forgotten and

git clone https://github.com/milkman3790/Humanity.git C:\dev\Humanity\Humanity — then read docs/5090_SETUP_RUNBOOK.md

and drive Stages 0-8. From here the on-box session owns everything — drivers and CUDA, cache env vars, the

three-drive layout, the watchers, the burn-in, firewall pre-authorization, the soak. Josh's remaining role is

physical asks (a cable reseat, a BIOS key) and the phone verification. [THE WALK-THROUGH MODE] Expect: the

session repeats the plan back and WAITS — nothing starts until after the reboot.

7 — THE BANDWIDTH KICKOFF (15 minutes of Josh, then it runs alone)

ORDER NOTE: run Section 8's ten-minute cold-reboot proof BEFORE starting anything here. A reboot restarts a `git

clone` from zero and ends the on-box session. Section 7 is written second because it is what you leave running.

51. Authenticate GitHub at the keyboard — credential-manager browser flow or gh auth login. [J5, 3.1] Expect:

gh auth status reports a signed-in GitHub account (or the credential-manager browser flow closed with a

success page). No prompt is left open. NON-NEGOTIABLE — item 7 cannot begin without it.

52. Let the on-box session start both clones to their exact old-machine paths and pull LFS fully. [4.1] Expect:

two clones running; a .uasset that is real content, not a 130-byte pointer.

53. Install the Epic Games Launcher and sign in. [J6, 3.5] Expect: the library page loads.

53b. Have the session start Unreal Engine 5.8.0 downloading. Expect: a progress bar and a GB figure moving. The

stage map budgets a two-to-four-hour tail — the single largest reason to start it tonight.

54. Let the session start the rest of the named pulls, bandwidth-first. The runbook enumerates them: the fastembed

embedding model [5.4], Ollama plus the Stage-5.3 tier ladder [5.1, 5.3 — the 14B pick is D-4, unresolved, the

runbook recommending two candidates pulled and A/B'd, plus the 7-8B, 3-4B and 0.6-1.7B rows], ComfyUI as the

image-lane host [6b], both VLM-OCR candidates [5.6, D-6]. Do not name a model the runbook does not — the

session picks from those rows and records what it pulled. The .rag/book_src transfer [D-12] is a local copy

from the old machine, not tonight's bandwidth.

54b. THE CONTINUO PRE-INSTALLS (accepted 2026-07-28, ~20 min of session time + overnight). Have the session:

(a) create D:\continuo, clone the Continuo repo there with its own Python 3.12 venv, and start

pip install -r requirements.txt; (b) copy Qwen2.5-14B-Instruct-Q4_K_M.gguf (~9GB) from the ROG Ally over

the LAN — never re-download it — then VERIFY sha256 against the ledger row (e47ad95d…c008), and start one

HF pull of the Q5_K_M (~10.3GB); (c) add a Defender / App-Control allow on D:\continuo\; (d) write

config.local.yaml with n_gpu_layers: -1, box-only, never committed. Continuo's models do NOT go in

HF_HOME and nothing goes outside that tree. [CONTINUO ADDITIONS block] Expect: the venv exists, the sha256

matches, and the Q5 pull is running. JOSH'S ONLY HANDS-ON PART: the Ally must be awake and on the LAN (step

8b) — confirm before you start section 8.

55. Do not wait for any of it, and do not watch it. SKIPPABLE to monitor.

DIRECTOR RULING, carried here rather than buried: Stage 0 says that until 0.7 verifies, every run is attended — and

0.7 cannot run tonight, because it needs a fully charged UPS. Downloads are resumable and hold no mid-write

registry or index state, a different risk class from an unattended soak or asset-gen job. RULED (director, 2026-07-28): resumable

downloads — git clones, HF and Ollama pulls, the UE engine download — are an EXPLICIT EXEMPTION from Stage 0's

attended-until-0.7 gate; they hold no mid-write registry or index state and resume from where a power event left

them. Soak runs and asset-generation lanes stay attended or deferred until 0.7 passes. Section 7 therefore runs

unattended tonight by ruling, not by exception-taking.

8 — THE COLD-REBOOT PROOF (10 minutes — the last gate before the airport)

56. Configure auto-logon: run netplwiz, uncheck "Users must enter a user name and password", enter the password

twice. [1.10, D-18 option (a), J4] Expect: the dialog closes without error. If the checkbox is missing, turn

off the Windows Hello sign-in requirement under Settings, Accounts, Sign-in options, then reopen netplwiz. Last

resort if the checkbox stays missing: the DefaultUserName / DefaultPassword / AutoAdminLogon registry pair

under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon — Josh types it, it is a stored

credential. NON-NEGOTIABLE (item 2) — the soak task is Interactive, and a machine that comes back to a lock screen gives

no soak, no window, and no remote reach.

57. Run manage-bde -status C: once more. Protection On with the key not escrowed: escrow it now. [J3]

58. Shut down from the Start menu. Expect: a clean power-off. If the menu offers only "Update and shut down,"

take it and budget the wait — or defer it via Settings, Windows Update, pause updates for one week, then

shut down clean.

59. While the machine is off, pull the UPS's wall plug for five seconds and watch the primary monitor and the

router. Expect: both stay live, the UPS alarms. Restore the plug immediately. [0.6 part (a), at reduced

confidence — it asks for a full charge you will not have.] Zero-risk with the machine off, and the only chance

for weeks to learn whether that bank really is the battery bank. If anything on it drops, step 12's wiring is

wrong: fix it now. Judge by the monitor's POWER LED and the router's link lights, not by the picture — the

machine is off, so the screen is dark either way. HANDS-ONLY, strongly recommended, not on the eight.

60. Press the power button and step away. Touch nothing — no keyboard, no monitor, no login. Expect: the machine

reaches the desktop by itself. (Step 25 only disabled the button while Windows is running — pressing it on a

powered-off machine still starts it.)

61. From the phone, still on cellular with Wi-Fi off, connect RustDesk again. Expect: the desktop, already logged

in, no Windows password prompt. Then repeat once on the 100.x address, as at step 45 — that is the

post-reboot proof of the Tailscale layer. [item 8] NON-NEGOTIABLE. When this passes, the evening's gate is met and Josh

is free to leave for the airport.

62. Reconnect over RustDesk, restart Claude Code in C:\dev, and run Section 7. Expect: clones and downloads

running when you close the Ally X.

SCOPE NOTE, stated honestly: tonight's proof covers auto-logon, the RustDesk service, and the network reconnect.

It does NOT prove the BIOS restore-on-AC link — that is 0.7's job and it needs a charged UPS and a hand at the

wall plug. Record it as an open gap, not a pass.

9 — IF THINGS GO WRONG

Only the eight checklist items are non-negotiable tonight. Everything else is remote-fixable, and skipping it

costs nothing.

BIOS trip has not happened yet. Try each port on the card, power-cycle once. Still nothing is a tier-(c)

hardware-suspect finding: stop the evening and call Puget while the RMA window is young. [abort rule, 0.1]

look for an address that is not 169.254.x.x. On Wi-Fi, re-enter the password. Fallback: tether the PC to the

phone's hotspot long enough to get Tailscale enrolled — with Tailscale up, everything else is fixable later.

list. If the PC shows expired or needs re-auth, re-authenticate now, at the keyboard — that is exactly the

fault that must never be discovered from abroad.

lock screen and a black screen look alike from a phone. Then plug the primary monitor back in and power it on;

a display-less output can present as black. The runbook is silent on RustDesk display behaviour, so tonight's

safe answer is to leave the primary monitor connected and powered, with only step 24's 15-minute blank. Still

black: skip it, the on-box session has a monitor to look at.

Beeping with wall power present is most likely a self-test on a low charge — let it charge and stop configuring

it. If it is genuinely faulting, run the tower straight to the wall tonight and let the on-box session redo

Stage 0 later. Checklist item 6 is the cable and the agent, not a proven battery.

CARRIED TO THE ON-BOX SESSION (so nothing here reads as done)

at the wall plug.

the posted benchmark/temperature baseline stand as the burn-in evidence of record; the on-box session runs a

light confirmation (brief load + nvidia-smi -q thermal/ECC read against Puget's posted numbers). Any delta

from Puget's own baseline is still a hardware-suspect stop.

Generated by harness/site/structure_site.py — the URL path is the repo path. review root