Skip to content

Add ARM64 support, signed dynamic data preparation, and Windows CI - #80

Merged
hzqst merged 31 commits into
masterfrom
dev
Aug 5, 2026
Merged

hzqst merged 31 commits into
masterfrom
dev

Conversation

@hzqst

@hzqst hzqst commented Aug 5, 2026

Copy link
Copy Markdown
Owner

Summary

  • replace the legacy driver implementation with KPH-backed kernel symbol and dynamic-data loading
  • add x64 and ARM64 solution configurations, signed dynamic-data preparation, and install/test-signing scripts
  • add Windows GitHub Actions builds for Debug/Release x64 and ARM64 plus release packaging
  • update documentation and repository metadata for the new build/runtime flow

Validation

  • msbuild VmLoader.sln /m /t:Rebuild /p:Configuration=Release /p:Platform=x64 — passed (0 warnings, 0 errors)
  • msbuild VmLoader.sln /m /t:Rebuild /p:Configuration=Release /p:Platform=ARM64 — passed (0 warnings, 0 errors)
  • KPH dynamic data: 3607 firmware records validated; signature verification passed

Runtime behavior was not exercised in a disposable Windows VM in this environment.

meowdiocre and others added 30 commits July 30, 2026 05:13
Replace kernel signature scanning with a user-mode resolver that stores validated RVAs for the matching Windows kernel.

BREAKING CHANGE: installation now requires vmloader_resolver.exe and valid registry symbol data before driver start.
- Rename RemoveSignatures to ReplaceInPlace to support pattern replacement instead of just removal
- Add Replacement parameter to enable substituting detected patterns with alternative strings
- Replace VMware/Virtual strings with System/Generic equivalents in firmware tables
- Add RemoveEnumerationEntry function to filter ACPI table entries from enumeration lists
- Add TableIdMatches helper to check table IDs in both native and reversed byte order
- Add RecomputeAcpiChecksum function to recalculate ACPI table checksums after modifications
- Implement WAET table filtering in FilterAcpi to prevent enumeration and return STATUS_NOT_FOUND
- Enhance FilterAcpi to handle both enumeration (Action 0) and table access (Action 1) requests
- Update FilterRsmb to use new ReplaceInPlace function with proper string substitution
- Fix loop boundary calculation in pattern search to prevent off-by-one errors
- Update compiled vmloader.sys binary with new firmware filtering logic
- Add new pnp_hook module with PnP callback registration and device filtering
- Implement case-insensitive pattern matching for VMware device detection (VEN_15AD, VID_0E0F)
- Filter PCI, USB, and HDAUDIO device enumeration to hide VMware devices
- Add registry key enumeration hooks to mask VMware presence from user-mode queries
- Integrate PnP hook installation and removal into driver lifecycle
- Update VmLoader.vcxproj and filters to include new source and header files
- Initialize PnP hooks during DriverEntry with proper error handling and cleanup
feat(symbols): resolve kernel globals from PDB
Co-Authored-By: Codex <codex@openai.com>
Co-Authored-By: Codex <codex@openai.com>
使用 PsLoadedModuleResource 共享锁保护。
遍历 PsLoadedModuleList,匹配 ntoskrnl.exe。
使用 RtlImageNtHeaderEx 按映像大小校验 PE 头。
增加异常捕获及完整的锁释放路径。
移除 MmGetSystemRoutineAddress + RtlPcToFileHeader 方案。
主要改动:
增加内核描述表,关联文件名、KPH class 和 fields size。
FindRunningKernel 按 KSI 顺序识别两种内核,并返回统一 identity。
external/embedded lookup 均向 KphDynDataLookup 传递实际 class。
保留原有 PE header、writable/non-executable section 和 RVA 校验。
增加日志输出实际内核名称与 class。
同步更新运行时文档。
自动申请管理员权限。
复用有效的 VmLoader Test Signing 证书。
缺失时生成 RSA 3072/SHA-256 测试证书。
将证书加入本机 Root 和 TrustedPublisher。
自动查找 Windows SDK signtool.exe。
签名并验证 VmLoader.sys。
主要改动:
移除 Win32/x86 工程与解决方案配置,默认平台改为 x64。
新增 Debug/Release ARM64 解决方案映射。
ARM64 启用 KPH 头文件、消息编译、ksecdd.lib、动态数据生成及签名。
ARM64 产物独立发布到 bin\ARM64,避免覆盖 x64。
同步更新 README 与 Serena 项目记忆。
@hzqst
hzqst merged commit b59b68e into master Aug 5, 2026
6 of 10 checks passed
@hzqst
hzqst deleted the dev branch August 5, 2026 16:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants