Skip to content

Implement Windows registry key syscalls - #1114

Merged
CvvT merged 6 commits into
uliteboxfrom
weiteng/windows_registry_key
Jul 31, 2026
Merged

Implement Windows registry key syscalls#1114
CvvT merged 6 commits into
uliteboxfrom
weiteng/windows_registry_key

Conversation

@CvvT

@CvvT CvvT commented Jul 31, 2026

Copy link
Copy Markdown
Contributor
  • Implement NtOpenKeyEx, NtCreateKey, NtQueryKey, and NtSetValueKey
  • Implement synchronous NtNotifyChangeKey notifications for value and subkey changes.
  • Asynchronous NtNotifyChangeKey, registry symbolic links, volatile keys, backup/restore privileges, and virtualization remain unsupported.

CvvT and others added 6 commits July 30, 2026 00:26
Decode and dispatch the extended registry-open syscall, validate native open options, and reuse the existing registry key resolution path with behavioral and host-fidelity coverage.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Support Basic, Node, Full, Name, Cached, and HandleTags information, including registry metadata and Windows-compatible buffer status behavior. Preserve explicit follow-ups for registry casing, timestamps, and virtualization.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Decode and dispatch the 10-argument NtNotifyChangeKey syscall through a NotifyChangeKeyParameters request struct. Gate on KEY_NOTIFY access, decode the REG_NOTIFY_CHANGE_* completion filter as bitflags, and reject unknown bits. The registry is a static store with no change-subscription mechanism, so an asynchronous registration returns STATUS_PENDING and is never completed, while a synchronous wait (which would block forever) returns STATUS_NOT_IMPLEMENTED. Tests assert the pending watch is not falsely completed by a later value write, plus the access, filter, and synchronous-mode contracts.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@CvvT
CvvT marked this pull request as ready for review July 31, 2026 22:40
@CvvT
CvvT added this pull request to the merge queue Jul 31, 2026
@github-actions

Copy link
Copy Markdown

🤖 SemverChecks 🤖 No breaking API changes detected

Note: this does not mean API is unchanged, or even that there are no breaking changes; simply, none of the detections triggered.

Merged via the queue into ulitebox with commit 7169693 Jul 31, 2026
8 checks passed
@CvvT
CvvT deleted the weiteng/windows_registry_key branch July 31, 2026 22:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant