Skip to content

Releases: HHT0rro/Xenolith

Xenolith v1.1.0-rc1 — Real-World Compatibility Release

Choose a tag to compare

@HHT0rro HHT0rro released this 24 Sep 21:22

Xenolith v1.1.0-rc1

打包器:规模与性能

  • 字符串常量区间发现由 O(n²) 重写为单趟状态机——此前 600 秒以上超时的大样本
    现在秒级完成(msys-2.0.dll:>600s → 0.87s)。
  • 密封页上限 16384 → 65535,与加载器真实 region 上限对齐。libcef/Electron 级
    单体可打包可加载(QQNT.dll 40631 页 18.8s;WeMeet WebCore 47813 页 23.7s)。
    lazy 模式超过 64 region 的镜像改为打包期 fail-closed,而非运行期静默出错。
  • 重定位收集从 O(region×page)(真实样本上高达 3.9×10¹⁰ 次比较)重写为
    有序不相交区间表 + 二分查找。
  • 打包峰值内存从约 5.5 倍输入降到约 2 倍:流水线每阶段对每个字节数组只保留
    一份(纯元数据页计划、删除死拷贝缓冲、envelope 用毕即弃)。61–231MB 的真实
    单体在并行打包下不再 OOM fail-fast。

打包器:格式覆盖

  • 紧凑节表布局:不再拒绝"放不下两个附加节头"的镜像,改为在首个 raw 数据前
    通过 FileAlignment 整数倍空洞扩展头部块。
  • 入口为 0 的纯资源 DLL 结构化打包——不偷入口字节、清 GUARD_CF 位、零 region
    envelope。entryless + TLS 回调组合显式 fail-closed 并给出明确报错;
    entryless + 无回调 TLS 目录字节保持地支持。
  • 重打包必然失效的 SECURITY(Authenticode)目录(绝对文件偏移)现在在
    所有输出路径统一清零。
  • 重定位保护改为重叠安全:区间先合并再二分,重叠可执行节不再静默丢失
    DIR64 重定位。

运行时与加载器

  • 模块目录感知的导入绑定,修复并定型。 此前 LoadLibraryExA 参数顺序 bug
    导致模块目录回退路径从未真正生效。绑定现为裸名优先(与系统加载器同一搜索
    序)、模块目录仅作显式回退;api-ms-/ext-ms- 虚拟名永不走路径回退——防止
    应用自带的陈旧系统 DLL(如随包 msvcrt)毒化后续系统导入。
  • 长 C++ 修饰导入名:255 字节固定缓冲 → 2048 字节(实测 MinGW 名长至 526 字节)。
  • 新增 FLAG_LOADER_RESOLVED_IAT:OS 加载器已解析导入目录时,stub 在 region
    密封前跳过冗余重绑定。
  • 末页保护按节恢复(不再硬编码 RX);stub 不再向只读页写静态缓冲(纯栈草稿区)。

已知限制(附完整证据链)

  • QQ.exe 及 QQEX 启动器链:沙箱子进程在任何代码运行之前就会执行/裁决落盘
    .text 字节(二分实验证实:密封页与噪声占位必死、明文存活)。密封形态无法
    满足该 pre-init 契约——属环境与磁盘密封的不相容,非 Xenolith 缺陷
    (--no-sandbox 可用)。opt-in"不密封 .text"档位列为可能的后续方向。
  • lazy-regions 模式对真实应用尚不可用(确定性重封 vs ASLR 重定位页),
    作为独立已知缺口跟踪。

Xenolith v1.1.0-rc1

Packer: scale & performance

  • String-constant interval discovery rewritten from O(n²) to a single-pass state
    machine — large binaries that previously timed out at 600s+ now pack in seconds
    (msys-2.0.dll: >600s → 0.87s).
  • Sealed-page cap raised 16384 → 65535, matching the loader's real region limit.
    libcef/Electron-class monoliths pack and load (QQNT.dll, 40,631 pages: 18.8s;
    WeMeet WebCore, 47,813 pages: 23.7s). Lazy-mode packs over 64 regions now fail
    closed at pack time instead of silently misbehaving at runtime.
  • Relocation collection rewritten from O(regions × pages) — up to 3.9×10¹⁰
    comparisons on real binaries — to a sorted disjoint-interval table with binary search.
  • Pack-time peak memory cut from ~5.5× to ~2× input size: the pipeline now keeps
    a single copy of each byte array per stage (metadata-only page plans, dead duplicate
    buffers removed, envelope dropped as soon as consumed). 61–231 MB real-world
    monoliths no longer OOM fail-fast under parallel packing.

Packer: format coverage

  • Tight section-table layouts: instead of rejecting images with no room for the two
    extra section headers, the header block is grown through a FileAlignment-sized hole
    before the first raw data.
  • Entry-less pure-resource DLLs (AddressOfEntryPoint = 0) are now packed
    structurally — no entry-byte stealing, GUARD_CF flag cleared, envelope with zero
    regions. Entry-less + TLS-callback combinations fail closed with a clear error;
    entry-less + callback-less TLS directories are supported byte-preserving.
  • The stale SECURITY (Authenticode) directory — whose absolute file offset is
    invalidated by any repack — is now cleared on every output path.
  • Relocation protection is now overlap-safe: protected ranges are merged before the
    binary search, so overlapping executable sections can no longer silently drop
    DIR64 relocations.

Runtime & loader

  • Module-directory-aware import binding, fixed and finalized. A LoadLibraryExA
    argument-order bug meant the module-dir fallback path had never actually worked.
    Binding is now bare-name-first (standard loader search order), with the module
    directory as explicit fallback; api-ms-/ext-ms- virtual names never take the
    path fallback — preventing app-local stale system DLLs (e.g. a bundled msvcrt)
    from poisoning subsequent system imports.
  • Long C++ mangled import names: fixed 255-byte buffers → 2048 bytes (MinGW names
    up to 526 bytes observed in the wild).
  • New FLAG_LOADER_RESOLVED_IAT: when the OS loader already resolved the import
    directory, the stub skips redundant rebinding before regions are sealed.
  • Final page protections restored per section instead of hardcoded RX; the stub no
    longer writes static buffers into read-only pages (stack-only scratch).

Known limitations (documented with full evidence chains)

  • QQ.exe and its QQEX launcher chain: sandboxed child processes execute/judge
    the on-disk .text bytes before any code runs (verified by bisection: sealed
    pages and noise placeholders die, plaintext survives). Sealed executables cannot
    survive this pre-init contract — this is an environment incompatibility with
    on-disk sealing, not a Xenolith defect (--no-sandbox works). An opt-in
    "unsealed .text" profile is a possible future direction.
  • The lazy-regions mode is not yet usable on real applications (deterministic
    re-seal vs ASLR-relocated pages) — tracked as an independent known gap.

Xenolith v1.0.0-rc.4

Choose a tag to compare

@HHT0rro HHT0rro released this 22 Sep 07:29

Real-world PE compatibility

Real, CFG-instrumented, ASLR-enabled system binaries now pack with --profile max and run byte-identically to their unpacked copies (verified on where/whoami/ping/tasklist/Robocopy/nslookup; delay-load images included).

  • GFIDS-aware packing — CFG images get a synthesized GuardCF function table (original entries + stub entry + export thunks, RVA-sorted); XFG and unknown guard formats fail closed.
  • ASLR boot fix — the loader's relocation delta is recovered from the 0xCC filler slots before decryption and DIR64 fixups are re-applied to decrypted pages; region AAD now binds the reloc-table byte length.
  • Delay-load imports accepted; .NET mixed-mode images refused with a named check.
  • Lift improvements — 64/8-bit operand width gating (previously silently mis-lowered), actionable errors carrying function + RVA + remediation, movzx/movsx/test/lea coverage with differential tests, ZF fusion with fail-closed invalidation, incremental-link jmp rel32 entry-thunk resolution, clean refusal on already-packed input.
  • Formats — ordinal imports, lossy ANSI names, structural bounds, PN_XNUM, imported IFUNC / TLSDESC / copy relocs accepted; TPOFF32-in-text and RELATIVE-into-sealed stay fail-closed.
  • TUI — type-to-filter, paged navigation, clearer progress and error presentation.

Verification

cargo test --workspace (32 suites), the ci-gates.ps1 strength suite (G-SIG / G-IAT / G-POLY / tamper SHA-256 / G-UPX), a 600 s bounded stress run, packed-vs-unpacked behavior equivalence on real system binaries, and both release-bundle regression legs on Windows and Ubuntu.

sha256 digests are in manifest.json inside each bundle.

Xenolith v1.0.0-rc.3

Choose a tag to compare

@HHT0rro HHT0rro released this 17 Sep 08:53

Xenolith v1.0.0-rc.3

首个公开发布的候选版本。

Xenolith 是开源的原生代码加壳器:输入 Windows x86_64 PE64 或 Linux AMD64 ELF64 二进制,输出带认证加密信封与自举 stub 的受保护映像。不需要源码,不需要重编译。核心设计是不做共享指令集虚拟机——选定导出在打包期被编译为逐块唯一的位置无关原生代码(superoperator),镜像中没有 guest 字节码、没有可复用的 opcode 表、没有中央分发器,每次打包都是一个新程序。

当前能力

  • PE64 打包:DLL/EXE 经系统 LoadLibrary/直接运行验证;ASLR、DEP/W^X、CFG/CET、TLS、SEH 展开元数据全部保留
  • 选择性虚拟化:--vm-export / --select-rva / --select-function / --select-all;函数发现覆盖命名导出、COFF 符号与 .pdata unwind 边界
  • W3 指令流发散(--trace-diverge):同输入同结果,指令流因进程而异(TEB⊕heap⊕RSP 硬币,禁用 RDTSC),朴素 trace 对齐失效
  • 信封加密:EnvelopeV2(XLV2)逐页 ChaCha20-Poly1305 + AAD 绑定;磁盘可执行页为 0xCC 陷阱字节;MBA 八肢体密钥分片,镜像中无连续主密钥
  • 注入运行时:手写 PIC boot stub + freestanding xl_core(无 CRT、无导入);RW→RX 页面翻转;哈希导入解析与 IAT 回填;stolen OEP;keyed FNV 篡改门(翻转一字节即加载失败);max 档反调试探针
  • ELF(实验):追加 R+X PT_LOAD + INIT_ARRAY[0] 自举,ld.so 仍是加载器;已在 Ubuntu 24.04 验证运行与 dlopen
  • CLI / TUI / 项目文件:四屏向导 TUI,未知项目键 fail closed,未接线开关不出现在任何界面
  • CI 强度门:G-UPX / G-SIG / G-IAT / G-OEP / G-DUMP / G-TAMPER / G-BEH / G-POLY / G-WB-* / G-VM 全部在打包产物上执行

已知边界(不吹不藏)

  • lift 窗口 256 字节;内存访问、调用、RIP 相对寻址、SEH、64 位数据 fail closed(可 --allow-native-fallback 如实报告为 mixed_native)
  • CRT 与 DllMain 永不虚拟化;虚拟化只覆盖选定导出
  • 解包后可执行页保持明文(C2 再加密未接线);暂停的进程可读当前页
  • W1/W2 默认档强度约在 OLLVM 层级(CFG 与原函数同构);质变从 W3 开始
  • 不可逆性、商业壳对等、"无限 AI 攻击失败"从来不是主张(白盒威胁模型 W0:源码 GPL 公开)

附件

xenolith-v1.0.0-rc.3-Windows.zip / xenolith-v1.0.0-rc.3-Linux.zip:CI 构建的发布 bundle,含工具二进制、SBOM、SHA-256 清单、来源(git commit、rustc 版本)与门证据。完整性以 manifest 内哈希为准(无代码签名)。

协议

GPL-3.0-or-later 附加 Stub Exception:被打包的程序按其自身许可分发,加壳不传染许可证。详见 LICENSE。